Description
An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11, 5.6.0 through 5.6.11 may allow an unauthenticated and remote attacker to access report template images via referencing the name in the URL path.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-30688 | An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11, 5.6.0 through 5.6.11 may allow an unauthenticated and remote attacker to access report template images via referencing the name in the URL path. |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-22-026 |
|
History
Wed, 25 Feb 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-10-22T20:53:41.416Z
Reserved: 2022-02-25T00:00:00.000Z
Link: CVE-2022-26121
Updated: 2024-08-03T04:56:37.398Z
Status : Modified
Published: 2022-10-10T14:15:09.727
Modified: 2024-11-21T06:53:28.427
Link: CVE-2022-26121
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD