Fortinet.FortiWeb.Web.Application.Firewall.Policy.Bypass

description-logoDescription

This indicates an attack attempt against a policy bypass vulnerability in Fortinet's FortiWeb Web Application Firewall.
The vulnerability is due to an input validation error when handling overly large HTTP requests. A remote attacker can exploit this to gain unauthorized access to sensitive information.

affected-products-logoAffected Products

Fortinet FortiWeb

Impact logoImpact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

recomended-action-logoRecommended Actions

Fortinet recommends to enable "Block Malformed Request" violation in "Protocol Constraints". In current versions of FortiWeb, this may be found under the Web Protection -> Protocol form.
Fortinet is working to a flexible solution for v4.3 Patch 7 which will further address this issue.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)