Inter ADOM information leakage

Summary

An improper access control vulnerability [CWE-284] in FortiManager and FortiAnalyzer management interface may allow a remote and authenticated admin user assigned to a specific ADOM to access other ADOMs information such as device information and dashboard information.

Affected Products

FortiManager version 7.2.0
FortiManager version 7.0.0 through 7.0.3
FortiManager version 6.4.0 through 6.4.7
FortiManager version 6.2.0 through 6.2.9
FortiManager version 6.0.0 through 6.0.11
FortiAnalyzer version 7.2.0
FortiAnalyzer version 7.0.0 through 7.0.3
FortiAnalyzer version 6.4.0 through 6.4.8
FortiAnalyzer version 6.2.0 through 6.2.10
FortiAnalyzer version 6.0.0 through 6.0.12

Solutions

Please upgrade to FortiManager version 7.2.1 or above
Please upgrade to FortiManager version 7.0.4 or above
Please upgrade to FortiManager version 6.4.8 or above
Please upgrade to FortiAnalyzer version 7.2.1 or above
Please upgrade to FortiAnalyzer version 7.0.4 or above
Please upgrade to FortiAnalyzer version 6.4.9 or above

Acknowledgement

Fortinet is pleased thank Abdulmohsen Nasser Alotaibi, from DEEM @ SDAIA for reporting this vulnerability under responsible disclosure.

Timeline

2022-09-06: Initial publication