CVE-2022-42477: Input Validation
An improper input validation vulnerability [CWE-20] in FortiAnalyzer version 7.2.1 and below, version 7.0.6 and below, 6.4 all versions may allow an authenticated attacker to disclose file system information via custom dataset SQL queries.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-42477?
CVE-2022-42477 is an improper input validation vulnerability in FortiAnalyzer version 7.2.1 and below.
What is the severity of CVE-2022-42477?
The severity of CVE-2022-42477 is high (CVSS severity rating of 5.5).
How does CVE-2022-42477 affect FortiAnalyzer?
CVE-2022-42477 may allow an authenticated attacker to disclose file system information via custom dataset SQL queries.
Which versions of FortiAnalyzer are affected by CVE-2022-42477?
FortiAnalyzer version 7.2.1 and below, version 7.0.6 and below, 6.4 all versions are affected by CVE-2022-42477.
How can I fix CVE-2022-42477?
To fix CVE-2022-42477, update FortiAnalyzer to version 7.0.7 or above for 7.x releases, or update to the latest version for 6.4.x releases.