A improper authentication vulnerability in Fortinet FortiSIEM before 6.5.0 allows a local attacker with CLI access to perform operations on the Glassfish server directly via a hardcoded password.
2022-11-02T12:15:50.427
2024-11-21T06:53:28.180
Modified
CVSSv3.1: 7.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortisiem | ≤ 5.1.3 | Yes |
Application | fortinet | fortisiem | ≤ 5.2.8 | Yes |
Application | fortinet | fortisiem | ≤ 5.3.3 | Yes |
Application | fortinet | fortisiem | ≤ 6.1.2 | Yes |
Application | fortinet | fortisiem | ≤ 6.3.3 | Yes |
Application | fortinet | fortisiem | 5.0.0 | Yes |
Application | fortinet | fortisiem | 5.0.1 | Yes |
Application | fortinet | fortisiem | 5.2.1 | Yes |
Application | fortinet | fortisiem | 5.2.2 | Yes |
Application | fortinet | fortisiem | 5.4.0 | Yes |
Application | fortinet | fortisiem | 6.2.0 | Yes |
Application | fortinet | fortisiem | 6.2.1 | Yes |
Application | fortinet | fortisiem | 6.4.0 | Yes |
Application | fortinet | fortisiem | 6.4.1 | Yes |