[FortiWLM] Unauthenticated limited file read vulnerability

Summary

A relative path traversal [CWE-23] in FortiWLM may allow a remote unauthenticated attacker to read sensitive files.

Version Affected Solution
FortiWLM 8.6 8.6.0 through 8.6.5 Upgrade to 8.6.6 or above
FortiWLM 8.5 8.5.0 through 8.5.4 Upgrade to 8.5.5 or above

Acknowledgement

Fortinet is pleased to thank security researcher Zach Hanley (@hacks_zach) of Horizon3.ai for discovering and reporting this vulnerability under responsible disclosure.

Timeline

2024-12-18: Initial publication