FortiWeb - heap-based buffer overflow in API v1.0 controller


A heap-based buffer overflow [CWE-122] vulnerability in FortiWeb may allow an authenticated attacker to execute arbitrary code or commands via crafted HTTP requests to the LogAccess and LogReport API controller.

Affected Products

FortiWeb version 6.4.1 and below.
FortiWeb version 6.3.16 and below.
FortiWeb version 6.2.6 and below.


Upgrade to FortiWeb version 7.0.0 or above.
Upgrade to FortiWeb version 6.4.2 or above.
Upgrade to FortiWeb version 6.3.17 or above.

Fix for FortiWeb versions 6.2 to be confirmed.


Internally discovered and reported by Mattia Fecit of Fortinet Product Security Team.