Heap-based buffer overflow in API v1.0 controller

Summary

A heap-based buffer overflow [CWE-122] vulnerability in FortiWeb may allow an authenticated attacker to execute arbitrary code or commands via crafted HTTP requests to the LogAccess and LogReport API controller.

Affected Products

FortiWeb version 6.4.1 and below.
FortiWeb version 6.3.16 and below.
FortiWeb version 6.2.6 and below.

Solutions

Upgrade to FortiWeb version 7.0.0 or above.
Upgrade to FortiWeb version 6.4.2 or above.
Upgrade to FortiWeb version 6.3.17 or above.
Fix for FortiWeb versions 6.2 to be confirmed.

Acknowledgement

Internally discovered and reported by Mattia Fecit of Fortinet Product Security Team.

Timeline

2021-12-07: Initial publication