An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiAnalyzer, FortiManager and FortiAnalyzer-BigData may allow a privileged attacker with read write administrative privileges to create non-arbitrary files on a chosen directory via crafted CLI requests.
A stack-based buffer overflow vulnerability [CWE-121] in FortiManager, FortiAnalyzer and FortiAnalyzer-BigData CLI may allow a privileged attacker to execute unauthorized code or commands via crafted CLI requests.
Multiple relative path traversal vulnerabilities [CWE-23] in FortiManager, FortiAnalyzer & FortiAnalyzer-BigData may allow a privileged attacker to delete files from the underlying filesystem via crafted CLI requests.
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiManager, FortiAnalyzer & FortiAnalyzer-BigData CLI may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests.
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiManager, FortiAnalyzer & FortiAnalyzer-BigData may allow a privileged attacker to read arbitrary files from the underlying system via crafted HTTP or HTTPs requests.
A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14 allows attacker to improper access control via crafted requests.
An Exposure of personal information to an unauthorized actor [CWE-359] in FortiManager, FortiAnalyzer & FortiAnalyzer-BigData may allow a privileged attacker with administrative read permissions to read event logs of another adom via crafted HTTP or HTTPs requests.
An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer & FortiManager may allow a remote attacker with low privileges to read sensitive data via a crafted HTTP request.