FG-IR-19-039: Server side request forgery on fortiview top threats report generation feature.
A server-side request forgery vulnerability [CWE-918] in FortiAnalyzer and FortiManager may allow a remote attacker with low privileges to view sensitive data from internal servers or perform a local port scan via a crafted HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-19-039?
The severity of FG-IR-19-039 is classified as a server-side request forgery vulnerability that can allow unauthorized access to sensitive data.
How do I fix FG-IR-19-039?
To fix FG-IR-19-039, you should upgrade to FortiAnalyzer and FortiManager version 7.4.1 or later, or other specified remedial versions.
Which products are affected by FG-IR-19-039?
FG-IR-19-039 affects FortiAnalyzer and FortiManager products in multiple versions, particularly those prior to the remedial versions listed.
What can attackers do with FG-IR-19-039?
Attackers exploiting FG-IR-19-039 can potentially view sensitive data from internal servers or perform local port scans.
Is there a known CVE ID associated with FG-IR-19-039?
The vulnerability FG-IR-19-039 does not have a known CVE ID associated with it at this time.