QID 377696
Date Published: 2022-10-31
QID 377696: FortiAnalyzer and FortiManager - Improper Authorization Vulnerability (FG-IR-22-026)
An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI may allow an unauthenticated and remote attacker to access report template images via referencing the name in the URL path.
Affected Products
FortiManager version 7.0.0 through 7.0.3
FortiManager 6.4 all versions
FortiManager 6.2 all versions
FortiManager 6.0 all versions
FortiManager 5.6 all versions
FortiAnalyzer version 7.0.0 through 7.0.3
FortiAnalyzer 6.4 all versions
FortiAnalyzer 6.2 all versions
FortiAnalyzer 6.0 all versions
FortiAnalyzer 5.6 all versions
QID Detection Logic(Authenticated):
QID will fire the command to get system status and will match the affected versions.
Vulnerable version may allow an unauthenticated and remote attacker to access report template images via referencing the name in the URL path
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-22-026
- FG-IR-22-026 -
www.fortiguard.com/psirt/FG-IR-22-026
CVEs related to QID 377696
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-026 |
|