PT-2021-23048 · Fortinet · Fortiweb

Published

2021-12-08

·

Updated

2021-12-10

·

CVE-2021-41013

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions FortiWeb versions 6.4.1 and below FortiWeb versions 6.3.15 and below
Description An improper access control issue in the Report Browse section of Log & Report may allow an unauthorized and unauthenticated user to access the Log reports via their URLs.
Recommendations For FortiWeb versions 6.4.1 and below, update to a version above 6.4.1 to resolve the issue. For FortiWeb versions 6.3.15 and below, update to a version above 6.3.15 to resolve the issue. As a temporary workaround, consider restricting access to the Report Browse section of Log & Report until a patch is available.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41013

Affected Products

Fortiweb