An improper input validation vulnerability [CWE-20] in FortiAnalyzer version 7.2.1 and below, version 7.0.6 and below, 6.4 all versions may allow an authenticated attacker to disclose file system information via custom dataset SQL queries.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortinet Fortianalyzer | — | Upgrade FortiAnalyzer to 7.4.2Upgrade FortiAnalyzer to 7.0.9Upgrade FortiAnalyzer to 6.2.12Upgrade FortiAnalyzer to 7.2.4Upgrade FortiAnalyzer to 6.4.13Upgrade to the latest version of FortiAnalyzer | Apr 20, 2023 | Apr 11, 2023 |
| Fortinet Fortimanager | — | Upgrade FortiManager to 7.2.4Upgrade FortiManager to 6.4.13Upgrade FortiManager to 7.4.2Upgrade FortiManager to 7.0.9Upgrade FortiManager to 6.2.12Upgrade to the latest version of FortiManager | May 25, 2026 | Apr 11, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub