FG-IR-22-026: Improper authorization to template image
An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI may allow an unauthenticatedand remote attacker to access report template images via referencing the name in the URL path.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-22-026?
The severity of FG-IR-22-026 is considered high, as it allows unauthorized access to sensitive report template images.
How do I fix FG-IR-22-026?
To fix FG-IR-22-026, update your FortiAnalyzer and FortiManager software to the latest version provided by Fortinet.
What impact does FG-IR-22-026 have on my system?
FG-IR-22-026 can expose confidential report template images to unauthorized users, potentially leading to data leakage.
Who is affected by FG-IR-22-026?
FG-IR-22-026 affects users of Fortinet FortiAnalyzer and FortiManager that are utilizing the GUI.
Is FG-IR-22-026 an authenticated or unauthenticated vulnerability?
FG-IR-22-026 is an unauthenticated vulnerability, which means remote attackers can exploit it without prior access.