Unauthorized user is granted access to the Reports available in the Log & Report section
Summary
An improper access control vulnerability [CWE-284] in the Report Browse section of FortiWeb's Log & Report may allow an unauthorized and unauthenticated user to access the Log reports via their URLs.
Affected Products
FortiWeb version 6.4.1 and below.
FortiWeb version 6.3.15 and below.
Solutions
Please upgrade to FortiWeb version 7.0.0 or above.
Please upgrade to FortiWeb version 6.4.2 or above.
Please upgrade to FortiWeb version 6.3.16 or above.
Acknowledgement
Fortinet is pleased to thank Bohdan Korzhynskyi (https://twitter.com/bohdansec) and Anton Korzhynskyi (https://twitter.com/tohasec) for reporting this vulnerability under responsible disclosure.Timeline
2021-12-07: Initial publication