An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11, 5.6.0 through 5.6.11 may allow an unauthenticated and remote attacker to access report template images via referencing the name in the URL path.
References
Link | Resource |
---|---|
https://fortiguard.com/psirt/FG-IR-22-026 | Vendor Advisory |
https://fortiguard.com/psirt/FG-IR-22-026 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 06:53
Type | Values Removed | Values Added |
---|---|---|
References | () https://fortiguard.com/psirt/FG-IR-22-026 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.7 |
12 Oct 2022, 18:44
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-10-10 14:15
Updated : 2024-11-21 06:53
NVD link : CVE-2022-26121
Mitre link : CVE-2022-26121
CVE.ORG link : CVE-2022-26121
JSON object : View
Products Affected
fortinet
- fortimanager
- fortianalyzer
CWE
CWE-668
Exposure of Resource to Wrong Sphere