Show filters
39 Total Results
Displaying 21-30 of 39
Sort by:
Attacker Value
Unknown
CVE-2023-25605
Disclosure Date: March 07, 2023 (last updated October 08, 2023)
A improper access control vulnerability in Fortinet FortiSOAR 7.3.0 - 7.3.1 allows an attacker authenticated on the administrative interface to perform unauthorized actions via crafted HTTP requests.
0
Attacker Value
Unknown
CVE-2023-0003
Disclosure Date: February 08, 2023 (last updated February 14, 2025)
A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server.
0
Attacker Value
Unknown
CVE-2022-38379
Disclosure Date: December 06, 2022 (last updated February 24, 2025)
Improper neutralization of input during web page generation [CWE-79] in FortiSOAR 7.0.0 through 7.0.3 and 7.2.0 may allow an authenticated attacker to inject HTML tags via input fields of various components within FortiSOAR.
0
Attacker Value
Unknown
CVE-2022-0031
Disclosure Date: November 09, 2022 (last updated February 24, 2025)
A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a local attacker with shell access to the engine to execute programs with elevated privileges.
0
Attacker Value
Unknown
CVE-2022-42473
Disclosure Date: November 02, 2022 (last updated February 24, 2025)
A missing authentication for a critical function vulnerability in Fortinet FortiSOAR 6.4.0 - 6.4.4 and 7.0.0 - 7.0.3 and 7.2.0 allows an attacker to disclose information via logging into the database using a privileged account without a password.
0
Attacker Value
Unknown
CVE-2022-29061
Disclosure Date: September 09, 2022 (last updated February 24, 2025)
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to execute unauthorized code or commands via crafted HTTP GET requests.
0
Attacker Value
Unknown
CVE-2022-35847
Disclosure Date: September 06, 2022 (last updated February 24, 2025)
An improper neutralization of special elements used in a template engine vulnerability [CWE-1336] in FortiSOAR management interface 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.4 may allow a remote and authenticated attacker to execute arbitrary code via a crafted payload.
0
Attacker Value
Unknown
CVE-2022-30298
Disclosure Date: September 06, 2022 (last updated February 24, 2025)
An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python commands as root.
0
Attacker Value
Unknown
CVE-2022-29062
Disclosure Date: September 06, 2022 (last updated February 24, 2025)
Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to write to the underlying filesystem with nginx permissions via crafted HTTP requests.
0
Attacker Value
Unknown
CVE-2022-0027
Disclosure Date: May 11, 2022 (last updated February 23, 2025)
An improper authorization vulnerability in Palo Alto Network Cortex XSOAR software enables authenticated users in non-Read-Only groups to generate an email report that contains summary information about all incidents in the Cortex XSOAR instance, including incidents to which the user does not have access. This issue impacts: All versions of Cortex XSOAR 6.1; All versions of Cortex XSOAR 6.2; All versions of Cortex XSOAR 6.5; Cortex XSOAR 6.6 versions earlier than Cortex XSOAR 6.6.0 build 6.6.0.2585049.
0