Unauthenticated arbitrary file read vulnerability
Summary
A relative path traversal vulnerability [CWE-23] in FortiWLM may allow a remote unauthenticated attacker to read arbitrary files via crafted HTTP requests.
Version | Affected | Solution |
---|---|---|
FortiWLM 8.6 | 8.6.0 through 8.6.5 | Upgrade to 8.6.6 or above |
FortiWLM 8.5 | 8.5.0 through 8.5.4 | Upgrade to 8.5.5 or above |
FortiWLM 8.4 | 8.4 all versions | Migrate to a fixed release |
FortiWLM 8.3 | 8.3 all versions | Migrate to a fixed release |
FortiWLM 8.2 | 8.2 all versions | Migrate to a fixed release |