Full path disclosure vulnerability
Summary
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiSIEM may allow an authenticated attacker to obtain the absolute path of files used by the supervisor, which could be dangerous if used in conjunction with other vulnerabilities.
Affected Products
FortiSIEM 7.0 all versions are not affectedFortiSIEM version 6.7.0 through 6.7.5
FortiSIEM 6.6 all versions are not affected
FortiSIEM 6.5 all versions are not affected
FortiSIEM 6.4 all versions are not affected
FortiSIEM 6.3 all versions are not affected
FortiSIEM 6.2 all versions are not affected
FortiSIEM 6.1 all versions are not affected
FortiSIEM 5.4 all versions are not affected
FortiSIEM 5.3 all versions are not affected
Solutions
Please upgrade to FortiSIEM version 7.0.0 or above
Please upgrade to FortiSIEM version 6.7.6 or above
Please upgrade to FortiSIEM version 6.6.0 or above