First published: Tue Apr 11 2023(Updated: )
An improper input validation vulnerability [CWE-20] in FortiAnalyzer version 7.2.1 and below, version 7.0.6 and below, 6.4 all versions may allow an authenticated attacker to disclose file system information via custom dataset SQL queries.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiAnalyzer | >=6.4.0<7.0.7 | |
Fortinet FortiAnalyzer | =7.2.0 |
Please upgrade to FortiAnalyzer version 7.2.2 or above Please upgrade to FortiAnalyzer version 7.0.7 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-42477 is an improper input validation vulnerability in FortiAnalyzer version 7.2.1 and below.
The severity of CVE-2022-42477 is high (CVSS severity rating of 5.5).
CVE-2022-42477 may allow an authenticated attacker to disclose file system information via custom dataset SQL queries.
FortiAnalyzer version 7.2.1 and below, version 7.0.6 and below, 6.4 all versions are affected by CVE-2022-42477.
To fix CVE-2022-42477, update FortiAnalyzer to version 7.0.7 or above for 7.x releases, or update to the latest version for 6.4.x releases.