PT-2022-22969 · Fortinet · Fortisoar

Published

2022-09-06

·

Updated

2023-08-08

·

CVE-2022-35847

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiSOAR management interface versions 6.4.0 through 6.4.4 FortiSOAR management interface versions 7.0.0 through 7.0.3 FortiSOAR management interface version 7.2.0
Description The issue is related to an improper neutralization of special elements used in a template engine, which may allow a remote and authenticated attacker to execute arbitrary code via a crafted payload.
Recommendations For FortiSOAR management interface versions 6.4.0 through 6.4.4, update to a version that contains a fix for this issue. For FortiSOAR management interface versions 7.0.0 through 7.0.3, update to a version that contains a fix for this issue. For FortiSOAR management interface version 7.2.0, update to a version that contains a fix for this issue.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2022-35847

Affected Products

Fortisoar