<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>IDOR on download logs feature</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-23-204</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2024-09-10T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2024-09-10T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2024-09-10T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer &amp; FortiManager may allow a remote attacker with low privileges to read sensitive data via a crafted HTTP request.
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Information disclosure
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="4">
            FortiManager 7.6 all versions are not affectedFortiManager version 7.4.0FortiManager version 7.2.0 through 7.2.4FortiManager 7.0 all versionsFortiManager 6.4 all versionsFortiManager 6.2 all versionsFortiAnalyzer-BigData 7.4 all versions are not affectedFortiAnalyzer-BigData version 7.2.0 through 7.2.5FortiAnalyzer 7.6 all versions are not affectedFortiAnalyzer version 7.4.0FortiAnalyzer version 7.2.0 through 7.2.4FortiAnalyzer 7.0 all versionsFortiAnalyzer 6.4 all versionsFortiAnalyzer 6.2 all versions
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="5">
            Please upgrade to FortiAnalyzer version 7.4.1 or abovePlease upgrade to FortiAnalyzer version 7.2.5 or abovePlease upgrade to FortiManager version 7.4.1 or abovePlease upgrade to FortiManager version 7.2.5 or abovePlease upgrade to FortiAnalyzer-BigData version 7.4.0 or abovePlease upgrade to FortiAnalyzer-BigData version 7.2.6 or above
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:DocumentReferences>
        <cvrf:Reference>
            <cvrf:URL>https://fortiguard.fortinet.com/psirt/FG-IR-23-204</cvrf:URL>
            <cvrf:Description>IDOR on download logs feature</cvrf:Description>
        </cvrf:Reference>
        <cvrf:Reference>
            <cvrf:URL>https://github.com/orangecertcc/security-research/security/advisories/GHSA-3xr4-2rgh-m245</cvrf:URL>
            <cvrf:Description>https://github.com/orangecertcc/security-research/security/advisories/GHSA-3xr4-2rgh-m245</cvrf:Description>
        </cvrf:Reference>
    </cvrf:DocumentReferences>
    <cvrf:Acknowledgments>
        <cvrf:Acknowledgment>
            <cvrf:Description>Fortinet is pleased to thank security researchers Mickael Dorigny at Orange Cyberdéfense, Frédéric Prevost, François-Xavier Picard and Orange CERT-CC at Orange group for discovering and reporting this vulnerability under responsible disclosure.</cvrf:Description>
        </cvrf:Acknowledgment>
    </cvrf:Acknowledgments>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiAnalyzer" Type="Product Name">
                <Branch Name="7.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.4.0">FortiAnalyzer 7.4.0</FullProductName>
                </Branch>
                <Branch Name="7.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.2.4">FortiAnalyzer 7.2.4</FullProductName>
                </Branch>
                <Branch Name="7.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.2.3">FortiAnalyzer 7.2.3</FullProductName>
                </Branch>
                <Branch Name="7.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.2.2">FortiAnalyzer 7.2.2</FullProductName>
                </Branch>
                <Branch Name="7.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.2.1">FortiAnalyzer 7.2.1</FullProductName>
                </Branch>
                <Branch Name="7.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.2.0">FortiAnalyzer 7.2.0</FullProductName>
                </Branch>
                <Branch Name="7.0.16" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.0.16">FortiAnalyzer 7.0.16</FullProductName>
                </Branch>
                <Branch Name="7.0.15" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.0.15">FortiAnalyzer 7.0.15</FullProductName>
                </Branch>
                <Branch Name="7.0.14" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.0.14">FortiAnalyzer 7.0.14</FullProductName>
                </Branch>
                <Branch Name="7.0.13" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.0.13">FortiAnalyzer 7.0.13</FullProductName>
                </Branch>
                <Branch Name="7.0.12" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.0.12">FortiAnalyzer 7.0.12</FullProductName>
                </Branch>
                <Branch Name="7.0.11" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.0.11">FortiAnalyzer 7.0.11</FullProductName>
                </Branch>
                <Branch Name="7.0.10" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.0.10">FortiAnalyzer 7.0.10</FullProductName>
                </Branch>
                <Branch Name="7.0.9" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.0.9">FortiAnalyzer 7.0.9</FullProductName>
                </Branch>
                <Branch Name="7.0.8" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.0.8">FortiAnalyzer 7.0.8</FullProductName>
                </Branch>
                <Branch Name="7.0.7" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.0.7">FortiAnalyzer 7.0.7</FullProductName>
                </Branch>
                <Branch Name="7.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.0.6">FortiAnalyzer 7.0.6</FullProductName>
                </Branch>
                <Branch Name="7.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.0.5">FortiAnalyzer 7.0.5</FullProductName>
                </Branch>
                <Branch Name="7.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.0.4">FortiAnalyzer 7.0.4</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.0.3">FortiAnalyzer 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.0.2">FortiAnalyzer 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.0.1">FortiAnalyzer 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.0.0">FortiAnalyzer 7.0.0</FullProductName>
                </Branch>
                <Branch Name="6.4.15" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.4.15">FortiAnalyzer 6.4.15</FullProductName>
                </Branch>
                <Branch Name="6.4.14" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.4.14">FortiAnalyzer 6.4.14</FullProductName>
                </Branch>
                <Branch Name="6.4.13" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.4.13">FortiAnalyzer 6.4.13</FullProductName>
                </Branch>
                <Branch Name="6.4.12" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.4.12">FortiAnalyzer 6.4.12</FullProductName>
                </Branch>
                <Branch Name="6.4.11" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.4.11">FortiAnalyzer 6.4.11</FullProductName>
                </Branch>
                <Branch Name="6.4.10" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.4.10">FortiAnalyzer 6.4.10</FullProductName>
                </Branch>
                <Branch Name="6.4.9" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.4.9">FortiAnalyzer 6.4.9</FullProductName>
                </Branch>
                <Branch Name="6.4.8" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.4.8">FortiAnalyzer 6.4.8</FullProductName>
                </Branch>
                <Branch Name="6.4.7" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.4.7">FortiAnalyzer 6.4.7</FullProductName>
                </Branch>
                <Branch Name="6.4.6" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.4.6">FortiAnalyzer 6.4.6</FullProductName>
                </Branch>
                <Branch Name="6.4.5" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.4.5">FortiAnalyzer 6.4.5</FullProductName>
                </Branch>
                <Branch Name="6.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.4.4">FortiAnalyzer 6.4.4</FullProductName>
                </Branch>
                <Branch Name="6.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.4.3">FortiAnalyzer 6.4.3</FullProductName>
                </Branch>
                <Branch Name="6.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.4.2">FortiAnalyzer 6.4.2</FullProductName>
                </Branch>
                <Branch Name="6.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.4.1">FortiAnalyzer 6.4.1</FullProductName>
                </Branch>
                <Branch Name="6.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.4.0">FortiAnalyzer 6.4.0</FullProductName>
                </Branch>
                <Branch Name="6.2.13" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.2.13">FortiAnalyzer 6.2.13</FullProductName>
                </Branch>
                <Branch Name="6.2.12" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.2.12">FortiAnalyzer 6.2.12</FullProductName>
                </Branch>
                <Branch Name="6.2.11" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.2.11">FortiAnalyzer 6.2.11</FullProductName>
                </Branch>
                <Branch Name="6.2.10" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.2.10">FortiAnalyzer 6.2.10</FullProductName>
                </Branch>
                <Branch Name="6.2.9" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.2.9">FortiAnalyzer 6.2.9</FullProductName>
                </Branch>
                <Branch Name="6.2.8" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.2.8">FortiAnalyzer 6.2.8</FullProductName>
                </Branch>
                <Branch Name="6.2.7" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.2.7">FortiAnalyzer 6.2.7</FullProductName>
                </Branch>
                <Branch Name="6.2.6" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.2.6">FortiAnalyzer 6.2.6</FullProductName>
                </Branch>
                <Branch Name="6.2.5" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.2.5">FortiAnalyzer 6.2.5</FullProductName>
                </Branch>
                <Branch Name="6.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.2.4">FortiAnalyzer 6.2.4</FullProductName>
                </Branch>
                <Branch Name="6.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.2.3">FortiAnalyzer 6.2.3</FullProductName>
                </Branch>
                <Branch Name="6.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.2.2">FortiAnalyzer 6.2.2</FullProductName>
                </Branch>
                <Branch Name="6.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.2.1">FortiAnalyzer 6.2.1</FullProductName>
                </Branch>
                <Branch Name="6.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.2.0">FortiAnalyzer 6.2.0</FullProductName>
                </Branch>
            </Branch>
            <Branch Name="FortiAnalyzer-BigData" Type="Product Name">
                <Branch Name="7.2.5" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-BigData-7.2.5">FortiAnalyzer-BigData 7.2.5</FullProductName>
                </Branch>
                <Branch Name="7.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-BigData-7.2.4">FortiAnalyzer-BigData 7.2.4</FullProductName>
                </Branch>
                <Branch Name="7.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-BigData-7.2.3">FortiAnalyzer-BigData 7.2.3</FullProductName>
                </Branch>
                <Branch Name="7.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-BigData-7.2.2">FortiAnalyzer-BigData 7.2.2</FullProductName>
                </Branch>
                <Branch Name="7.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-BigData-7.2.1">FortiAnalyzer-BigData 7.2.1</FullProductName>
                </Branch>
                <Branch Name="7.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-BigData-7.2.0">FortiAnalyzer-BigData 7.2.0</FullProductName>
                </Branch>
            </Branch>
            <Branch Name="FortiManager" Type="Product Name">
                <Branch Name="7.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.4.0">FortiManager 7.4.0</FullProductName>
                </Branch>
                <Branch Name="7.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.2.4">FortiManager 7.2.4</FullProductName>
                </Branch>
                <Branch Name="7.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.2.3">FortiManager 7.2.3</FullProductName>
                </Branch>
                <Branch Name="7.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.2.2">FortiManager 7.2.2</FullProductName>
                </Branch>
                <Branch Name="7.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.2.1">FortiManager 7.2.1</FullProductName>
                </Branch>
                <Branch Name="7.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.2.0">FortiManager 7.2.0</FullProductName>
                </Branch>
                <Branch Name="7.0.16" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.0.16">FortiManager 7.0.16</FullProductName>
                </Branch>
                <Branch Name="7.0.15" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.0.15">FortiManager 7.0.15</FullProductName>
                </Branch>
                <Branch Name="7.0.14" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.0.14">FortiManager 7.0.14</FullProductName>
                </Branch>
                <Branch Name="7.0.13" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.0.13">FortiManager 7.0.13</FullProductName>
                </Branch>
                <Branch Name="7.0.12" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.0.12">FortiManager 7.0.12</FullProductName>
                </Branch>
                <Branch Name="7.0.11" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.0.11">FortiManager 7.0.11</FullProductName>
                </Branch>
                <Branch Name="7.0.10" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.0.10">FortiManager 7.0.10</FullProductName>
                </Branch>
                <Branch Name="7.0.9" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.0.9">FortiManager 7.0.9</FullProductName>
                </Branch>
                <Branch Name="7.0.8" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.0.8">FortiManager 7.0.8</FullProductName>
                </Branch>
                <Branch Name="7.0.7" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.0.7">FortiManager 7.0.7</FullProductName>
                </Branch>
                <Branch Name="7.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.0.6">FortiManager 7.0.6</FullProductName>
                </Branch>
                <Branch Name="7.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.0.5">FortiManager 7.0.5</FullProductName>
                </Branch>
                <Branch Name="7.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.0.4">FortiManager 7.0.4</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.0.3">FortiManager 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.0.2">FortiManager 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.0.1">FortiManager 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.0.0">FortiManager 7.0.0</FullProductName>
                </Branch>
                <Branch Name="6.4.15" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.4.15">FortiManager 6.4.15</FullProductName>
                </Branch>
                <Branch Name="6.4.14" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.4.14">FortiManager 6.4.14</FullProductName>
                </Branch>
                <Branch Name="6.4.13" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.4.13">FortiManager 6.4.13</FullProductName>
                </Branch>
                <Branch Name="6.4.12" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.4.12">FortiManager 6.4.12</FullProductName>
                </Branch>
                <Branch Name="6.4.11" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.4.11">FortiManager 6.4.11</FullProductName>
                </Branch>
                <Branch Name="6.4.10" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.4.10">FortiManager 6.4.10</FullProductName>
                </Branch>
                <Branch Name="6.4.9" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.4.9">FortiManager 6.4.9</FullProductName>
                </Branch>
                <Branch Name="6.4.8" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.4.8">FortiManager 6.4.8</FullProductName>
                </Branch>
                <Branch Name="6.4.7" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.4.7">FortiManager 6.4.7</FullProductName>
                </Branch>
                <Branch Name="6.4.6" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.4.6">FortiManager 6.4.6</FullProductName>
                </Branch>
                <Branch Name="6.4.5" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.4.5">FortiManager 6.4.5</FullProductName>
                </Branch>
                <Branch Name="6.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.4.4">FortiManager 6.4.4</FullProductName>
                </Branch>
                <Branch Name="6.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.4.3">FortiManager 6.4.3</FullProductName>
                </Branch>
                <Branch Name="6.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.4.2">FortiManager 6.4.2</FullProductName>
                </Branch>
                <Branch Name="6.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.4.1">FortiManager 6.4.1</FullProductName>
                </Branch>
                <Branch Name="6.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.4.0">FortiManager 6.4.0</FullProductName>
                </Branch>
                <Branch Name="6.2.13" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.2.13">FortiManager 6.2.13</FullProductName>
                </Branch>
                <Branch Name="6.2.12" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.2.12">FortiManager 6.2.12</FullProductName>
                </Branch>
                <Branch Name="6.2.11" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.2.11">FortiManager 6.2.11</FullProductName>
                </Branch>
                <Branch Name="6.2.10" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.2.10">FortiManager 6.2.10</FullProductName>
                </Branch>
                <Branch Name="6.2.9" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.2.9">FortiManager 6.2.9</FullProductName>
                </Branch>
                <Branch Name="6.2.8" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.2.8">FortiManager 6.2.8</FullProductName>
                </Branch>
                <Branch Name="6.2.7" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.2.7">FortiManager 6.2.7</FullProductName>
                </Branch>
                <Branch Name="6.2.6" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.2.6">FortiManager 6.2.6</FullProductName>
                </Branch>
                <Branch Name="6.2.5" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.2.5">FortiManager 6.2.5</FullProductName>
                </Branch>
                <Branch Name="6.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.2.4">FortiManager 6.2.4</FullProductName>
                </Branch>
                <Branch Name="6.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.2.3">FortiManager 6.2.3</FullProductName>
                </Branch>
                <Branch Name="6.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.2.2">FortiManager 6.2.2</FullProductName>
                </Branch>
                <Branch Name="6.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.2.1">FortiManager 6.2.1</FullProductName>
                </Branch>
                <Branch Name="6.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.2.0">FortiManager 6.2.0</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>IDOR on download logs feature</Title>
        <cvrf:CVE>CVE-2023-44254</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiAnalyzer-7.4.0</ProductID>
                <ProductID>FortiAnalyzer-7.2.4</ProductID>
                <ProductID>FortiAnalyzer-7.2.3</ProductID>
                <ProductID>FortiAnalyzer-7.2.2</ProductID>
                <ProductID>FortiAnalyzer-7.2.1</ProductID>
                <ProductID>FortiAnalyzer-7.2.0</ProductID>
                <ProductID>FortiAnalyzer-7.0.16</ProductID>
                <ProductID>FortiAnalyzer-7.0.15</ProductID>
                <ProductID>FortiAnalyzer-7.0.14</ProductID>
                <ProductID>FortiAnalyzer-7.0.13</ProductID>
                <ProductID>FortiAnalyzer-7.0.12</ProductID>
                <ProductID>FortiAnalyzer-7.0.11</ProductID>
                <ProductID>FortiAnalyzer-7.0.10</ProductID>
                <ProductID>FortiAnalyzer-7.0.9</ProductID>
                <ProductID>FortiAnalyzer-7.0.8</ProductID>
                <ProductID>FortiAnalyzer-7.0.7</ProductID>
                <ProductID>FortiAnalyzer-7.0.6</ProductID>
                <ProductID>FortiAnalyzer-7.0.5</ProductID>
                <ProductID>FortiAnalyzer-7.0.4</ProductID>
                <ProductID>FortiAnalyzer-7.0.3</ProductID>
                <ProductID>FortiAnalyzer-7.0.2</ProductID>
                <ProductID>FortiAnalyzer-7.0.1</ProductID>
                <ProductID>FortiAnalyzer-7.0.0</ProductID>
                <ProductID>FortiAnalyzer-6.4.15</ProductID>
                <ProductID>FortiAnalyzer-6.4.14</ProductID>
                <ProductID>FortiAnalyzer-6.4.13</ProductID>
                <ProductID>FortiAnalyzer-6.4.12</ProductID>
                <ProductID>FortiAnalyzer-6.4.11</ProductID>
                <ProductID>FortiAnalyzer-6.4.10</ProductID>
                <ProductID>FortiAnalyzer-6.4.9</ProductID>
                <ProductID>FortiAnalyzer-6.4.8</ProductID>
                <ProductID>FortiAnalyzer-6.4.7</ProductID>
                <ProductID>FortiAnalyzer-6.4.6</ProductID>
                <ProductID>FortiAnalyzer-6.4.5</ProductID>
                <ProductID>FortiAnalyzer-6.4.4</ProductID>
                <ProductID>FortiAnalyzer-6.4.3</ProductID>
                <ProductID>FortiAnalyzer-6.4.2</ProductID>
                <ProductID>FortiAnalyzer-6.4.1</ProductID>
                <ProductID>FortiAnalyzer-6.4.0</ProductID>
                <ProductID>FortiAnalyzer-6.2.13</ProductID>
                <ProductID>FortiAnalyzer-6.2.12</ProductID>
                <ProductID>FortiAnalyzer-6.2.11</ProductID>
                <ProductID>FortiAnalyzer-6.2.10</ProductID>
                <ProductID>FortiAnalyzer-6.2.9</ProductID>
                <ProductID>FortiAnalyzer-6.2.8</ProductID>
                <ProductID>FortiAnalyzer-6.2.7</ProductID>
                <ProductID>FortiAnalyzer-6.2.6</ProductID>
                <ProductID>FortiAnalyzer-6.2.5</ProductID>
                <ProductID>FortiAnalyzer-6.2.4</ProductID>
                <ProductID>FortiAnalyzer-6.2.3</ProductID>
                <ProductID>FortiAnalyzer-6.2.2</ProductID>
                <ProductID>FortiAnalyzer-6.2.1</ProductID>
                <ProductID>FortiAnalyzer-6.2.0</ProductID>
                <ProductID>FortiAnalyzer-BigData-7.2.5</ProductID>
                <ProductID>FortiAnalyzer-BigData-7.2.4</ProductID>
                <ProductID>FortiAnalyzer-BigData-7.2.3</ProductID>
                <ProductID>FortiAnalyzer-BigData-7.2.2</ProductID>
                <ProductID>FortiAnalyzer-BigData-7.2.1</ProductID>
                <ProductID>FortiAnalyzer-BigData-7.2.0</ProductID>
                <ProductID>FortiManager-7.4.0</ProductID>
                <ProductID>FortiManager-7.2.4</ProductID>
                <ProductID>FortiManager-7.2.3</ProductID>
                <ProductID>FortiManager-7.2.2</ProductID>
                <ProductID>FortiManager-7.2.1</ProductID>
                <ProductID>FortiManager-7.2.0</ProductID>
                <ProductID>FortiManager-7.0.16</ProductID>
                <ProductID>FortiManager-7.0.15</ProductID>
                <ProductID>FortiManager-7.0.14</ProductID>
                <ProductID>FortiManager-7.0.13</ProductID>
                <ProductID>FortiManager-7.0.12</ProductID>
                <ProductID>FortiManager-7.0.11</ProductID>
                <ProductID>FortiManager-7.0.10</ProductID>
                <ProductID>FortiManager-7.0.9</ProductID>
                <ProductID>FortiManager-7.0.8</ProductID>
                <ProductID>FortiManager-7.0.7</ProductID>
                <ProductID>FortiManager-7.0.6</ProductID>
                <ProductID>FortiManager-7.0.5</ProductID>
                <ProductID>FortiManager-7.0.4</ProductID>
                <ProductID>FortiManager-7.0.3</ProductID>
                <ProductID>FortiManager-7.0.2</ProductID>
                <ProductID>FortiManager-7.0.1</ProductID>
                <ProductID>FortiManager-7.0.0</ProductID>
                <ProductID>FortiManager-6.4.15</ProductID>
                <ProductID>FortiManager-6.4.14</ProductID>
                <ProductID>FortiManager-6.4.13</ProductID>
                <ProductID>FortiManager-6.4.12</ProductID>
                <ProductID>FortiManager-6.4.11</ProductID>
                <ProductID>FortiManager-6.4.10</ProductID>
                <ProductID>FortiManager-6.4.9</ProductID>
                <ProductID>FortiManager-6.4.8</ProductID>
                <ProductID>FortiManager-6.4.7</ProductID>
                <ProductID>FortiManager-6.4.6</ProductID>
                <ProductID>FortiManager-6.4.5</ProductID>
                <ProductID>FortiManager-6.4.4</ProductID>
                <ProductID>FortiManager-6.4.3</ProductID>
                <ProductID>FortiManager-6.4.2</ProductID>
                <ProductID>FortiManager-6.4.1</ProductID>
                <ProductID>FortiManager-6.4.0</ProductID>
                <ProductID>FortiManager-6.2.13</ProductID>
                <ProductID>FortiManager-6.2.12</ProductID>
                <ProductID>FortiManager-6.2.11</ProductID>
                <ProductID>FortiManager-6.2.10</ProductID>
                <ProductID>FortiManager-6.2.9</ProductID>
                <ProductID>FortiManager-6.2.8</ProductID>
                <ProductID>FortiManager-6.2.7</ProductID>
                <ProductID>FortiManager-6.2.6</ProductID>
                <ProductID>FortiManager-6.2.5</ProductID>
                <ProductID>FortiManager-6.2.4</ProductID>
                <ProductID>FortiManager-6.2.3</ProductID>
                <ProductID>FortiManager-6.2.2</ProductID>
                <ProductID>FortiManager-6.2.1</ProductID>
                <ProductID>FortiManager-6.2.0</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>4.7</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N/E:P/RL:X/RC:X</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-23-204</URL>
                <Description>IDOR on download logs feature</Description>
            </Reference>Reference>
            <Reference>
                <URL>https://github.com/orangecertcc/security-research/security/advisories/GHSA-3xr4-2rgh-m245</URL>
                <Description>https://github.com/orangecertcc/security-research/security/advisories/GHSA-3xr4-2rgh-m245</Description>
            </Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>