First published: Mon Oct 10 2022(Updated: )
An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI may allow an unauthenticatedand remote attacker to access report template images via referencing the name in the URL path.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiAnalyzer | ||
Fortinet FortiManager |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of FG-IR-22-026 is considered high, as it allows unauthorized access to sensitive report template images.
To fix FG-IR-22-026, update your FortiAnalyzer and FortiManager software to the latest version provided by Fortinet.
FG-IR-22-026 can expose confidential report template images to unauthorized users, potentially leading to data leakage.
FG-IR-22-026 affects users of Fortinet FortiAnalyzer and FortiManager that are utilizing the GUI.
FG-IR-22-026 is an unauthenticated vulnerability, which means remote attackers can exploit it without prior access.