FortiWeb - Unauthorized Configuration Download Vulnerability
Summary
An unauthorized configuration download vulnerability [CWE-285] in FortiWeb may allow a local attacker to access confidential configuration files via a crafted http request.
Affected Products
FortiWeb 7.2 all versions are not affectedFortiWeb version 7.0.0 through 7.0.4
FortiWeb 6.4 all versions
FortiWeb version 6.3.6 through 6.3.23
FortiWeb 6.2 all versions are not affected
FortiWeb 6.1 all versions are not affected
Solutions
Please upgrade to FortiWeb version 7.0.5 or above.
Please upgrade to FortiWeb version 7.2.0 or above.