Blind SQL injection in Update/Create case component

Summary

An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiSIEM Update/Create Case feature may allow an authenticated attacker to extract database information via crafted requests.

Version Affected Solution
FortiSIEM 7.3 Not affected Not Applicable
FortiSIEM 7.2 Not affected Not Applicable
FortiSIEM 7.1 7.1 all versions Migrate to a fixed release
FortiSIEM 7.0 7.0 all versions Migrate to a fixed release
FortiSIEM 6.7 6.7 all versions Migrate to a fixed release
FortiSIEM 6.6 6.6 all versions Migrate to a fixed release
FortiSIEM 6.5 6.5 all versions Migrate to a fixed release
FortiSIEM 6.4 6.4 all versions Migrate to a fixed release
FortiSIEM 6.3 Not affected Not Applicable
FortiSIEM 6.2 Not affected Not Applicable
FortiSIEM 6.1 Not affected Not Applicable
FortiSIEM 5.4 Not affected Not Applicable

Acknowledgement

Fortinet is pleased to thank Adel T. Mouneer from Cyshield for reporting this vulnerability under responsible disclosure.

Timeline

2025-01-14: Initial publication