SQL injections in sdnproxy daemon

Summary

An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiManager and FortiAnalyzer may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted requests.

Version Affected Solution
FortiAnalyzer 7.6 Not affected Not Applicable
FortiAnalyzer 7.4 7.4.0 through 7.4.3 Upgrade to 7.4.4 or above
FortiAnalyzer 7.2 Not affected Not Applicable
FortiAnalyzer 7.0 Not affected Not Applicable
FortiAnalyzer Cloud 7.4 7.4.1 through 7.4.2 Upgrade to 7.4.3 or above
FortiManager Cloud 7.4 7.4.1 through 7.4.2 Upgrade to 7.4.3 or above
FortiManager 7.6 Not affected Not Applicable
FortiManager 7.4 7.4.0 through 7.4.2 Upgrade to 7.4.3 or above
FortiManager 7.2 Not affected Not Applicable
FortiManager 7.0 Not affected Not Applicable

Acknowledgement

Internally discovered and reported by Gwendal Guégniaud of Fortinet Product Security team.

Timeline

2025-01-14: Initial publication