CVE-2022-26121
Summary
| CVE | CVE-2022-26121 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-10 14:15:00 UTC |
| Updated | 2022-10-12 18:44:00 UTC |
| Description | An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11, 5.6.0 through 5.6.11 may allow an unauthenticated and remote attacker to access report template images via referencing the name in the URL path. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| PSIRT Advisories | FortiGuard |
CONFIRM |
fortiguard.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377696 FortiAnalyzer and FortiManager - Improper Authorization Vulnerability (FG-IR-22-026)
- 43934 FortiAnalyzer and FortiManager - improper authorization to template image (FG-IR-22-026)