QID 377724
Date Published: 2022-11-01
QID 377724: FortiManager - ADOMs Script Information Leakage Vulnerability (FG-IR-21-103)
An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiManager may allow a FortiGate user to see scripts from other ADOMS.
Affected Products:
FortiManager version 7.0.1 and below.
FortiManager version 6.4.6 and below.
FortiManager version 6.2.x.
FortiManager version 6.0.x.
FortiManager version 5.6.x.
QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiManager.
Vulnerable version may allow a FortiGate user to see scripts from other ADOMs.
Solution
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-21-103
Vendor References
- FG-IR-21-103 -
www.fortiguard.com/psirt/FG-IR-21-103
CVEs related to QID 377724
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-21-103 |
|