First published: Tue Sep 10 2024(Updated: )
An improper access control vulnerability [CWE-284] in FortiEDR Manager API 6.2.0 through 6.2.2, 6.0 all versions may allow in a shared environment context an authenticated admin with REST API permissions in his profile and restricted to a specific organization to access backend logs that include information related to other organizations.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet Fortiedrmanager | >=6.2.0<6.2.2 | |
Fortinet Fortiedrmanager | =6.0.1 |
Please upgrade to FortiEDR Manager version 6.2.3 or above Please upgrade to FortiEDR Manager version 6.0.2 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.