An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11, 5.6.0 through 5.6.11 may allow an unauthenticated and remote attacker to access report template images via referencing the name in the URL path.
References
Link | Resource |
---|---|
https://fortiguard.com/psirt/FG-IR-22-026 | Vendor Advisory |
https://fortiguard.com/psirt/FG-IR-22-026 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 06:53
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.7 |
References | () https://fortiguard.com/psirt/FG-IR-22-026 - Vendor Advisory |
Information
Published : 2022-10-10 14:15
Updated : 2024-11-21 06:53
NVD link : CVE-2022-26121
Mitre link : CVE-2022-26121
CVE.ORG link : CVE-2022-26121
JSON object : View
Products Affected
fortinet
- fortimanager
- fortianalyzer
CWE
CWE-668
Exposure of Resource to Wrong Sphere