Full path disclosure vulnerability

Summary

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiSIEM may allow an authenticated attacker to obtain the absolute path of files used by the supervisor, which could be dangerous if used in conjunction with other vulnerabilities.

Affected Products

FortiSIEM version 6.7.0 through 6.7.5

Solutions

Please upgrade to FortiSIEM version 7.0.0 or above
Please upgrade to FortiSIEM version 6.7.6 or above
Please upgrade to FortiSIEM version 6.6.0 or above

Acknowledgement

Internally discovered and reported by Adham El karn of Fortinet Product Security team.

Timeline

2023-09-07: Initial publication