Arbitrary file write on GUI
Summary
A relative path traversal vulnerability [CWE-23] in FortiManager & FortiAnalyzer may allow a privileged attacker with super-admin profile and CLI access to write files on the underlying system via crafted HTTP or HTTPS requests.
| Version | Affected | Solution |
|---|---|---|
| FortiAnalyzer 7.6 | Not affected | Not Applicable |
| FortiAnalyzer 7.4 | 7.4.0 through 7.4.3 | Upgrade to 7.4.4 or above |
| FortiAnalyzer 7.2 | 7.2.0 through 7.2.5 | Upgrade to 7.2.6 or above |
| FortiAnalyzer 7.0 | 7.0.2 through 7.0.12 | Upgrade to 7.0.13 or above |
| FortiAnalyzer 6.4 | Not affected | Not Applicable |
| FortiAnalyzer 6.2 | 6.2.10 through 6.2.13 | Migrate to a fixed release |
| FortiManager 7.6 | Not affected | Not Applicable |
| FortiManager 7.4 | 7.4.0 through 7.4.3 | Upgrade to 7.4.4 or above |
| FortiManager 7.2 | 7.2.0 through 7.2.5 | Upgrade to 7.2.6 or above |
| FortiManager 7.0 | 7.0.2 through 7.0.12 | Upgrade to 7.0.13 or above |
| FortiManager 6.4 | Not affected | Not Applicable |
| FortiManager 6.2 | 6.2.10 through 6.2.13 | Migrate to a fixed release |