Unauthorized user is granted access to the Reports available in the Log & Report section

Summary

An improper access control vulnerability [CWE-284] in the Report Browse section of FortiWeb's Log & Report may allow an unauthorized and unauthenticated user to access the Log reports via their URLs.

Affected Products

FortiWeb version 6.4.1 and below.
FortiWeb version 6.3.15 and below.

Solutions

Please upgrade to FortiWeb version 7.0.0 or above.
Please upgrade to FortiWeb version 6.4.2 or above.
Please upgrade to FortiWeb version 6.3.16 or above.

Acknowledgement

Fortinet is pleased to thank Bohdan Korzhynskyi (https://twitter.com/bohdansec) and Anton Korzhynskyi (https://twitter.com/tohasec) for reporting this vulnerability under responsible disclosure.

Timeline

2021-12-07: Initial publication