Improper Handling of Insufficient Permissions or Privileges in GUI websocket

Summary

An Improper Handling of Insufficient Permissions or Privileges Vulnerability [CWE-280] in FortiPAM and FortiSRA GUI websocket could allow a low privileged user to access to a unauthorized resources via specially crafted http requests.

Version Affected Solution
FortiPAM 1.6 Not affected Not Applicable
FortiPAM 1.5 Not affected Not Applicable
FortiPAM 1.4 1.4.0 through 1.4.1 Upgrade to 1.4.2 or above
FortiPAM 1.3 1.3.0 Upgrade to 1.3.1 or above
FortiPAM 1.2 1.2.0 Upgrade to upcoming 1.2.1 or above
FortiPAM 1.1 1.1.0 through 1.1.2 Upgrade to upcoming 1.1.3 or above
FortiPAM 1.0 1.0.0 through 1.0.3 Upgrade to upcoming 1.0.4 or above
FortiSRA 1.6 Not affected Not Applicable
FortiSRA 1.5 Not affected Not Applicable
FortiSRA 1.4 1.4.0 through 1.4.1 Upgrade to 1.4.2 or above

Acknowledgement

Internally discovered and reported by Gwendal Guégniaud of Fortinet Product Security team.

Timeline

2025-06-10: Initial publication