CVE-2022-42477
11.04.2023, 17:15
An improper input validation vulnerability [CWE-20] in FortiAnalyzer version 7.2.1 and below, version 7.0.6 and below, 6.4 all versions may allow an authenticated attacker to disclose file system information via custom dataset SQL queries.Enginsight
Vendor | Product | Version |
---|---|---|
fortinet | fortianalyzer | 6.4.0 ≤ 𝑥 < 7.0.7 |
fortinet | fortianalyzer | 7.2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration