CVE-2022-39945: Medium severity fortinet fortimail-200d vulnerability
An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, 6.0 all versions may allow an authenticated admin user assigned to a specific domain to access and modify other domains information via insecure direct object references (IDOR).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this FortiMail vulnerability?
The vulnerability ID of this FortiMail vulnerability is CVE-2022-39945.
What is the severity of CVE-2022-39945?
The severity of CVE-2022-39945 is medium (6.5).
Which software versions are affected by CVE-2022-39945?
FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, and 6.0 all versions are affected by CVE-2022-39945.
How does CVE-2022-39945 impact FortiMail?
CVE-2022-39945 allows an authenticated admin user assigned to a specific domain to access and modify other domains' information via insecure direct object references.
Is there a fix available for CVE-2022-39945?
It is recommended to update FortiMail to a version that is not affected by CVE-2022-39945.