QID 378396
Date Published: 2023-04-13
QID 378396: Fortinet FortiAnalyzer Improper Input Validation Vulnerability (FG-IR-22-432)
An improper input validation vulnerability in FortiAnalyzer may allow an authenticated attacker to disclose file system information via custom dataset SQL queries.
Affected Products:
FortiAnalyzer version 7.2.1 and below
FortiAnalyzer version 7.0.6 and below
FortiAnalyzer version 6.4 all versions
QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiAnalyzer.
Successful exploitation of this vulnerability may allow an authenticated attacker to disclose file system information via custom dataset SQL queries.
Solution
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-22-432
Vendor References
- FG-IR-22-432 -
www.fortiguard.com/psirt/FG-IR-22-432
CVEs related to QID 378396
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-432 |
|