<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>Glassfish local credentials stored in plain text</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-22-064</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2022-11-01T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2022-11-01T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2022-11-01T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            An improper authentification vulnerability [CWE-287] in FortiSIEM may allow a local attacker with CLI access to perform operations on the Glassfish server directly via a hardcoded password.
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Improper access control
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="4">
            At leastFortiSIEM 6.6 all versions are not affectedFortiSIEM 6.5 all versions are not affectedFortiSIEM 6.4 all versionsFortiSIEM 6.3 all versionsFortiSIEM 6.2 all versionsFortiSIEM 6.1 all versionsFortiSIEM 5.4 all versionsFortiSIEM 5.3 all versionsFortiSIEM 5.2 all versionsFortiSIEM 5.1 all versionsFortiSIEM 5.0 all versions
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="5">
            Please upgrade to FortiSIEM version 6.5.0 or above
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:Acknowledgments>
        <cvrf:Acknowledgment>
            <cvrf:Description>Fortinet is pleased to thank Victor Pasman and James Reno for reporting this vulnerability under responsible disclosure.</cvrf:Description>
        </cvrf:Acknowledgment>
    </cvrf:Acknowledgments>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiSIEM" Type="Product Name">
                <Branch Name="6.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.4.4">FortiSIEM 6.4.4</FullProductName>
                </Branch>
                <Branch Name="6.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.4.3">FortiSIEM 6.4.3</FullProductName>
                </Branch>
                <Branch Name="6.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.4.2">FortiSIEM 6.4.2</FullProductName>
                </Branch>
                <Branch Name="6.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.4.1">FortiSIEM 6.4.1</FullProductName>
                </Branch>
                <Branch Name="6.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.4.0">FortiSIEM 6.4.0</FullProductName>
                </Branch>
                <Branch Name="6.3.3" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.3.3">FortiSIEM 6.3.3</FullProductName>
                </Branch>
                <Branch Name="6.3.2" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.3.2">FortiSIEM 6.3.2</FullProductName>
                </Branch>
                <Branch Name="6.3.1" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.3.1">FortiSIEM 6.3.1</FullProductName>
                </Branch>
                <Branch Name="6.3.0" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.3.0">FortiSIEM 6.3.0</FullProductName>
                </Branch>
                <Branch Name="6.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.2.1">FortiSIEM 6.2.1</FullProductName>
                </Branch>
                <Branch Name="6.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.2.0">FortiSIEM 6.2.0</FullProductName>
                </Branch>
                <Branch Name="6.1.2" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.1.2">FortiSIEM 6.1.2</FullProductName>
                </Branch>
                <Branch Name="6.1.1" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.1.1">FortiSIEM 6.1.1</FullProductName>
                </Branch>
                <Branch Name="6.1.0" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.1.0">FortiSIEM 6.1.0</FullProductName>
                </Branch>
                <Branch Name="5.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-5.4.0">FortiSIEM 5.4.0</FullProductName>
                </Branch>
                <Branch Name="5.3.3" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-5.3.3">FortiSIEM 5.3.3</FullProductName>
                </Branch>
                <Branch Name="5.3.2" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-5.3.2">FortiSIEM 5.3.2</FullProductName>
                </Branch>
                <Branch Name="5.3.1" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-5.3.1">FortiSIEM 5.3.1</FullProductName>
                </Branch>
                <Branch Name="5.3.0" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-5.3.0">FortiSIEM 5.3.0</FullProductName>
                </Branch>
                <Branch Name="5.2.8" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-5.2.8">FortiSIEM 5.2.8</FullProductName>
                </Branch>
                <Branch Name="5.2.7" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-5.2.7">FortiSIEM 5.2.7</FullProductName>
                </Branch>
                <Branch Name="5.2.6" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-5.2.6">FortiSIEM 5.2.6</FullProductName>
                </Branch>
                <Branch Name="5.2.5" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-5.2.5">FortiSIEM 5.2.5</FullProductName>
                </Branch>
                <Branch Name="5.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-5.2.2">FortiSIEM 5.2.2</FullProductName>
                </Branch>
                <Branch Name="5.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-5.2.1">FortiSIEM 5.2.1</FullProductName>
                </Branch>
                <Branch Name="5.1.3" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-5.1.3">FortiSIEM 5.1.3</FullProductName>
                </Branch>
                <Branch Name="5.1.2" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-5.1.2">FortiSIEM 5.1.2</FullProductName>
                </Branch>
                <Branch Name="5.1.1" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-5.1.1">FortiSIEM 5.1.1</FullProductName>
                </Branch>
                <Branch Name="5.1.0" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-5.1.0">FortiSIEM 5.1.0</FullProductName>
                </Branch>
                <Branch Name="5.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-5.0.1">FortiSIEM 5.0.1</FullProductName>
                </Branch>
                <Branch Name="5.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-5.0.0">FortiSIEM 5.0.0</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>Glassfish local credentials stored in plain text</Title>
        <cvrf:CVE>CVE-2022-26119</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiSIEM-6.4.4</ProductID>
                <ProductID>FortiSIEM-6.4.3</ProductID>
                <ProductID>FortiSIEM-6.4.2</ProductID>
                <ProductID>FortiSIEM-6.4.1</ProductID>
                <ProductID>FortiSIEM-6.4.0</ProductID>
                <ProductID>FortiSIEM-6.3.3</ProductID>
                <ProductID>FortiSIEM-6.3.2</ProductID>
                <ProductID>FortiSIEM-6.3.1</ProductID>
                <ProductID>FortiSIEM-6.3.0</ProductID>
                <ProductID>FortiSIEM-6.2.1</ProductID>
                <ProductID>FortiSIEM-6.2.0</ProductID>
                <ProductID>FortiSIEM-6.1.2</ProductID>
                <ProductID>FortiSIEM-6.1.1</ProductID>
                <ProductID>FortiSIEM-6.1.0</ProductID>
                <ProductID>FortiSIEM-5.4.0</ProductID>
                <ProductID>FortiSIEM-5.3.3</ProductID>
                <ProductID>FortiSIEM-5.3.2</ProductID>
                <ProductID>FortiSIEM-5.3.1</ProductID>
                <ProductID>FortiSIEM-5.3.0</ProductID>
                <ProductID>FortiSIEM-5.2.8</ProductID>
                <ProductID>FortiSIEM-5.2.7</ProductID>
                <ProductID>FortiSIEM-5.2.6</ProductID>
                <ProductID>FortiSIEM-5.2.5</ProductID>
                <ProductID>FortiSIEM-5.2.2</ProductID>
                <ProductID>FortiSIEM-5.2.1</ProductID>
                <ProductID>FortiSIEM-5.1.3</ProductID>
                <ProductID>FortiSIEM-5.1.2</ProductID>
                <ProductID>FortiSIEM-5.1.1</ProductID>
                <ProductID>FortiSIEM-5.1.0</ProductID>
                <ProductID>FortiSIEM-5.0.1</ProductID>
                <ProductID>FortiSIEM-5.0.0</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>7.4</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:C</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-22-064</URL>
                <Description>Glassfish local credentials stored in plain text</Description>
            </Reference>Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>