An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11, 5.6.0 through 5.6.11 may allow an unauthenticated and remote attacker to access report template images via referencing the name in the URL path.
References
Link | Resource |
---|---|
https://fortiguard.com/psirt/FG-IR-22-026 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2022-10-10 07:15
Updated : 2022-10-12 11:44
NVD link : CVE-2022-26121
Mitre link : CVE-2022-26121
JSON object : View
CWE
CWE-668
Exposure of Resource to Wrong Sphere
Products Affected
fortinet
- fortianalyzer
- fortimanager