CVE-2022-26121
EUVD-2022-3068810.10.2022, 14:15
An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11, 5.6.0 through 5.6.11 may allow an unauthenticated and remote attacker to access report template images via referencing the name in the URL path.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| fortinet | fortimanager | 5.6.0 < 𝑥 ≤ 5.6.11 |
| fortinet | fortimanager | 6.0.0 < 𝑥 ≤ 6.0.11 |
| fortinet | fortimanager | 6.2.0 < 𝑥 ≤ 6.2.9 |
| fortinet | fortimanager | 6.4.0 < 𝑥 ≤ 6.4.8 |
| fortinet | fortimanager | 7.0.0 < 𝑥 ≤ 7.0.3 |
| fortinet | fortianalyzer | 5.6.0 < 𝑥 ≤ 5.6.11 |
| fortinet | fortianalyzer | 6.0.0 < 𝑥 ≤ 6.0.11 |
| fortinet | fortianalyzer | 6.2.0 < 𝑥 ≤ 6.2.9 |
| fortinet | fortianalyzer | 6.4.0 < 𝑥 ≤ 6.4.8 |
| fortinet | fortianalyzer | 7.0.0 < 𝑥 ≤ 7.0.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration