FG-IR-22-522: Improper privilege management on API requests
An improper privilege management vulnerability [CWE-269] in FortiManager and FortiAnalyzer API may allow a remote and authenticated API admin user to access some system settings such as the mail server settings through the API via a stolen GUI session ID.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-22-522?
The severity of FG-IR-22-522 is high due to the potential for unauthorized access to sensitive system settings.
How do I fix FG-IR-22-522?
To fix FG-IR-22-522, update FortiManager and FortiAnalyzer to versions 7.2.3 or later, 7.0.8 or later, or 6.4.12 or later, depending on your version.
Who is affected by FG-IR-22-522?
FG-IR-22-522 affects FortiManager and FortiAnalyzer versions below the specified remedial versions.
What type of vulnerability is FG-IR-22-522?
FG-IR-22-522 is an improper privilege management vulnerability that allows API admin users to access certain system settings.
Can FG-IR-22-522 be exploited remotely?
Yes, FG-IR-22-522 can be exploited remotely by an authenticated user, allowing unauthorized system access.