Unauthorized ADOM operations

Summary

Multiple improper authorization vulnerabilities [CWE-285] in FortiWeb may allow an authenticated attacker to perform unauthorized ADOM operations via crafted requests.

Version Affected Solution
FortiWeb 7.4 7.4.0 through 7.4.2 Upgrade to 7.4.3 or above
FortiWeb 7.2 7.2.0 through 7.2.7 Upgrade to 7.2.8 or above
FortiWeb 7.0 7.0 all versions Migrate to a fixed release
FortiWeb 6.4 6.4 all versions Migrate to a fixed release
FortiWeb 6.3 6.3 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Leslie Zhou of Fortinet Vulnerability Research team.

Timeline

2024-05-14: Initial publication