First published: Tue May 12 2015(Updated: )
Cross-site scripting (XSS) vulnerability in the advanced dataset reports page in Fortinet FortiAnalyzer 5.0.0 through 5.0.10 and 5.2.0 through 5.2.1 and FortiManager 5.0.3 through 5.0.10 and 5.2.0 through 5.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiManager | =5.0.3 | |
Fortinet FortiManager | =5.0.4 | |
Fortinet FortiManager | =5.0.5 | |
Fortinet FortiManager | =5.0.6 | |
Fortinet FortiManager | =5.0.7 | |
Fortinet FortiManager | =5.0.8 | |
Fortinet FortiManager | =5.0.9 | |
Fortinet FortiManager | =5.0.10 | |
Fortinet FortiManager | =5.2.0 | |
Fortinet FortiManager | =5.2.1 | |
Fortinet FortiAnalyzer | =5.0.0 | |
Fortinet FortiAnalyzer | =5.0.1 | |
Fortinet FortiAnalyzer | =5.0.10 | |
Fortinet FortiAnalyzer | =5.2.0 | |
Fortinet FortiAnalyzer | =5.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3620 has been rated as a medium severity vulnerability.
To fix CVE-2015-3620, update FortiManager or FortiAnalyzer to the latest patched version.
CVE-2015-3620 affects Fortinet FortiAnalyzer versions 5.0.0 to 5.0.10 and 5.2.0 to 5.2.1, as well as FortiManager versions 5.0.3 to 5.0.10 and 5.2.0 to 5.2.1.
CVE-2015-3620 is a Cross-site Scripting (XSS) vulnerability.
Organizations using affected versions of Fortinet FortiManager or FortiAnalyzer are at risk from CVE-2015-3620.