{"id":19294,"date":"2024-11-17T21:58:16","date_gmt":"2024-11-17T21:58:16","guid":{"rendered":"https:\/\/www.directimpactsolutions.com\/?p=19294"},"modified":"2024-11-17T22:01:00","modified_gmt":"2024-11-17T22:01:00","slug":"votre-serveur-filemaker-est-il-plus-ancien-que-la-version-19-6-vos-donnees-sont-peut-etre-vulnerables","status":"publish","type":"post","link":"https:\/\/www.directimpactsolutions.com\/fr\/votre-serveur-filemaker-est-il-plus-ancien-que-la-version-19-6-vos-donnees-sont-peut-etre-vulnerables\/","title":{"rendered":"Votre serveur FileMaker est-il plus ancien que la version 19.6 ? Vos donn\u00e9es sont peut-\u00eatre vuln\u00e9rables"},"content":{"rendered":"<p><strong>Une importante faille de s\u00e9curit\u00e9 a r\u00e9cemment \u00e9t\u00e9 d\u00e9couverte dans toutes les anciennes versions de FileMaker Server. N&rsquo;importe qui peut entrer via FileMaker Pro ou FileMaker Pro Advanced et obtenir un acc\u00e8s complet \u00e0 n&rsquo;importe quelle base de donn\u00e9es h\u00e9berg\u00e9e sur FileMaker Server. <\/strong>Cela est possible sans conna\u00eetre le nom du fichier ou les noms de compte.<\/p><p>Si vous utilisez une version de FileMaker Server ant\u00e9rieure \u00e0 la version 19.6.4, vous devez lire cet article tr\u00e8s attentivement et agir rapidement pour r\u00e9soudre le probl\u00e8me.<\/p><p><strong>FileMaker Server n&rsquo;affiche pas les connexions en place qui exploitent la faille dans la console d&rsquo;administration ou dans les journaux.<\/strong> En fait, vous n&rsquo;avez pas la possibilit\u00e9 d&rsquo;intercepter l&rsquo;intrusion en temps r\u00e9el ou de v\u00e9rifier que quelqu&rsquo;un a eu un acc\u00e8s non autoris\u00e9 aux fichiers.<\/p><h3 class=\"wp-block-heading\" id=\"When-Was-this-Discovered?\">Quand cette faille a-t-elle \u00e9t\u00e9 d\u00e9couverte ?<\/h3><p>La faille a \u00e9t\u00e9 d\u00e9couverte \u00e0 l&rsquo;automne 2023 ; Claris a \u00e9t\u00e9 inform\u00e9e et a rem\u00e9di\u00e9 au probl\u00e8me en avril 2024, mais uniquement \u00e0 partir de FileMaker 20.3.2 et sur FileMaker Server 19.6.4.<\/p><h4 class=\"wp-block-heading\" id=\"So-It&#x2019;s-Fixed?\">Le probl\u00e8me est donc r\u00e9solu ?<\/h4><p>Au contraire : toutes les versions de FileMaker Server ant\u00e9rieures \u00e0 la version 19.6 et accessibles depuis un r\u00e9seau sont vuln\u00e9rables. Il n&rsquo;y a aucun moyen de savoir, du c\u00f4t\u00e9 de FileMaker, si quelqu&rsquo;un a compromis le syst\u00e8me. <\/p><figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1014\" height=\"681\" src=\"https:\/\/www.directimpactsolutions.com\/wp-content\/uploads\/2024\/11\/d349f6b0-c38b-408c-95ce-2bf8a23fa5a2.jpeg\" alt=\"\" class=\"wp-image-19285\" style=\"width:600px\" srcset=\"https:\/\/www.directimpactsolutions.com\/wp-content\/uploads\/2024\/11\/d349f6b0-c38b-408c-95ce-2bf8a23fa5a2.jpeg 1014w, https:\/\/www.directimpactsolutions.com\/wp-content\/uploads\/2024\/11\/d349f6b0-c38b-408c-95ce-2bf8a23fa5a2-300x201.jpeg 300w, https:\/\/www.directimpactsolutions.com\/wp-content\/uploads\/2024\/11\/d349f6b0-c38b-408c-95ce-2bf8a23fa5a2-768x516.jpeg 768w, https:\/\/www.directimpactsolutions.com\/wp-content\/uploads\/2024\/11\/d349f6b0-c38b-408c-95ce-2bf8a23fa5a2-600x403.jpeg 600w\" sizes=\"auto, (max-width: 1014px) 100vw, 1014px\" \/><\/figure><p><\/p><p>Mais comment une telle situation a-t-elle pu se produire ? D&rsquo;un point de vue technique, le probl\u00e8me d\u00e9pend de trois facteurs : <\/p><ul class=\"wp-block-list\"><li>Le protocole utilis\u00e9 par FileMaker pour communiquer entre le client et le serveur<\/li>\n\n<li>La fa\u00e7on dont FileMaker Server identifie les bases de donn\u00e9es h\u00e9berg\u00e9es<\/li>\n\n<li>La m\u00e9thode par laquelle le moteur FileMaker (Draco) g\u00e8re les utilisateurs<\/li><\/ul><h3 class=\"wp-block-heading\" id=\"The-Solution?-Upgrade-FileMaker-Server-to-at-least-Version-19.6.4.\">La solution ? Mettez \u00e0 jour FileMaker Server avec au moins la version 19.6.4. <\/h3><p>Bien que des outils tels que les VPN ou autres r\u00e9duisent le risque d&rsquo;acc\u00e8s ind\u00e9sirable, le fait de ne pas mettre \u00e0 niveau et de fermer l&rsquo;acc\u00e8s externe au serveur n&rsquo;est pas une solution permanente. En fait, une importante vuln\u00e9rabilit\u00e9 du r\u00e9seau interne subsiste. <\/p><p>Vous ne savez pas comment mettre \u00e0 jour FileMaker Server ? <a href=\"https:\/\/www.directimpactsolutions.com\/fr\/contact\/\">\u00c9crivez-nous maintenant !<\/a><\/p><p><\/p>","protected":false},"excerpt":{"rendered":"<p>Une importante faille de s\u00e9curit\u00e9 a r\u00e9cemment \u00e9t\u00e9 d\u00e9couverte dans toutes les anciennes versions de FileMaker Server. N&rsquo;importe qui peut entrer via FileMaker Pro ou FileMaker Pro Advanced et obtenir un acc\u00e8s complet \u00e0 n&rsquo;importe quelle base de donn\u00e9es h\u00e9berg\u00e9e sur FileMaker Server. Cela est possible sans conna\u00eetre le nom du fichier ou les noms &hellip;<\/p>\n<p class=\"read-more\"> <a class=\"\" href=\"https:\/\/www.directimpactsolutions.com\/fr\/votre-serveur-filemaker-est-il-plus-ancien-que-la-version-19-6-vos-donnees-sont-peut-etre-vulnerables\/\"> <span class=\"screen-reader-text\">Votre serveur FileMaker est-il plus ancien que la version 19.6 ? Vos donn\u00e9es sont peut-\u00eatre vuln\u00e9rables<\/span> Lire la suite >><\/a><\/p>\n","protected":false},"author":6,"featured_media":19297,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_uag_custom_page_level_css":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"","footnotes":""},"categories":[35],"tags":[],"class_list":["post-19294","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-nouvelles"],"uagb_featured_image_src":{"full":["https:\/\/www.directimpactsolutions.com\/wp-content\/uploads\/2024\/11\/2a3cb3d8-f49d-4d12-99fd-08b19d9d4ab3-1-1.jpeg",999,629,false],"thumbnail":["https:\/\/www.directimpactsolutions.com\/wp-content\/uploads\/2024\/11\/2a3cb3d8-f49d-4d12-99fd-08b19d9d4ab3-1-1-150x150.jpeg",150,150,true],"medium":["https:\/\/www.directimpactsolutions.com\/wp-content\/uploads\/2024\/11\/2a3cb3d8-f49d-4d12-99fd-08b19d9d4ab3-1-1-300x189.jpeg",300,189,true],"medium_large":["https:\/\/www.directimpactsolutions.com\/wp-content\/uploads\/2024\/11\/2a3cb3d8-f49d-4d12-99fd-08b19d9d4ab3-1-1-768x484.jpeg",768,484,true],"large":["https:\/\/www.directimpactsolutions.com\/wp-content\/uploads\/2024\/11\/2a3cb3d8-f49d-4d12-99fd-08b19d9d4ab3-1-1.jpeg",999,629,false],"1536x1536":["https:\/\/www.directimpactsolutions.com\/wp-content\/uploads\/2024\/11\/2a3cb3d8-f49d-4d12-99fd-08b19d9d4ab3-1-1.jpeg",999,629,false],"2048x2048":["https:\/\/www.directimpactsolutions.com\/wp-content\/uploads\/2024\/11\/2a3cb3d8-f49d-4d12-99fd-08b19d9d4ab3-1-1.jpeg",999,629,false],"woocommerce_thumbnail":["https:\/\/www.directimpactsolutions.com\/wp-content\/uploads\/2024\/11\/2a3cb3d8-f49d-4d12-99fd-08b19d9d4ab3-1-1-300x300.jpeg",300,300,true],"woocommerce_single":["https:\/\/www.directimpactsolutions.com\/wp-content\/uploads\/2024\/11\/2a3cb3d8-f49d-4d12-99fd-08b19d9d4ab3-1-1-600x378.jpeg",600,378,true],"woocommerce_gallery_thumbnail":["https:\/\/www.directimpactsolutions.com\/wp-content\/uploads\/2024\/11\/2a3cb3d8-f49d-4d12-99fd-08b19d9d4ab3-1-1-100x100.jpeg",100,100,true]},"uagb_author_info":{"display_name":"Direct Impact Solutions","author_link":"https:\/\/www.directimpactsolutions.com\/fr\/author\/direct-impact-solutions\/"},"uagb_comment_info":0,"uagb_excerpt":"Une importante faille de s\u00e9curit\u00e9 a r\u00e9cemment \u00e9t\u00e9 d\u00e9couverte dans toutes les anciennes versions de FileMaker Server. N&rsquo;importe qui peut entrer via FileMaker Pro ou FileMaker Pro Advanced et obtenir un acc\u00e8s complet \u00e0 n&rsquo;importe quelle base de donn\u00e9es h\u00e9berg\u00e9e sur FileMaker Server. Cela est possible sans conna\u00eetre le nom du fichier ou les noms\u2026","_links":{"self":[{"href":"https:\/\/www.directimpactsolutions.com\/fr\/wp-json\/wp\/v2\/posts\/19294","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.directimpactsolutions.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.directimpactsolutions.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.directimpactsolutions.com\/fr\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.directimpactsolutions.com\/fr\/wp-json\/wp\/v2\/comments?post=19294"}],"version-history":[{"count":2,"href":"https:\/\/www.directimpactsolutions.com\/fr\/wp-json\/wp\/v2\/posts\/19294\/revisions"}],"predecessor-version":[{"id":21077,"href":"https:\/\/www.directimpactsolutions.com\/fr\/wp-json\/wp\/v2\/posts\/19294\/revisions\/21077"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.directimpactsolutions.com\/fr\/wp-json\/wp\/v2\/media\/19297"}],"wp:attachment":[{"href":"https:\/\/www.directimpactsolutions.com\/fr\/wp-json\/wp\/v2\/media?parent=19294"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.directimpactsolutions.com\/fr\/wp-json\/wp\/v2\/categories?post=19294"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.directimpactsolutions.com\/fr\/wp-json\/wp\/v2\/tags?post=19294"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}