Show filters
173 Total Results
Displaying 41-50 of 173
Sort by:
Attacker Value
Unknown

CVE-2024-23666

Disclosure Date: November 12, 2024 (last updated January 22, 2025)
A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14 allows attacker to improper access control via crafted requests.
Attacker Value
Unknown

CVE-2023-44255

Disclosure Date: November 12, 2024 (last updated January 22, 2025)
An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a privileged attacker with administrative read permissions to read event logs of another adom via crafted HTTP or HTTPs requests.
Attacker Value
Unknown

CVE-2020-11859

Disclosure Date: November 06, 2024 (last updated November 09, 2024)
Improper Input Validation vulnerability in OpenText iManager allows Cross-Site Scripting (XSS). This issue affects iManager before 3.2.3
Attacker Value
Unknown

CVE-2024-33506

Disclosure Date: October 08, 2024 (last updated January 22, 2025)
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7.2.5 and below, 7.0.12 and below allows a remote authenticated attacker assigned to an Administrative Domain (ADOM) to access device summary of unauthorized ADOMs via crafted HTTP requests.
Attacker Value
Unknown

CVE-2023-44254

Disclosure Date: September 10, 2024 (last updated December 21, 2024)
An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.2.5 and FortiManager version 7.4.1 and before 7.2.5 may allow a remote attacker with low privileges to read sensitive data via a crafted HTTP request.
Attacker Value
Unknown

CVE-2024-21757

Disclosure Date: August 13, 2024 (last updated August 23, 2024)
A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, allows an attacker to modify admin passwords via the device configuration backup.
Attacker Value
Unknown

CVE-2024-4429

Disclosure Date: May 28, 2024 (last updated January 22, 2025)
Cross-Site Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to sensitive information disclosure.
Attacker Value
Unknown

CVE-2024-3969

Disclosure Date: May 28, 2024 (last updated January 22, 2025)
XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to remote code execution by parsing untrusted XML payload
Attacker Value
Unknown

CVE-2024-3969

Disclosure Date: May 28, 2024 (last updated January 22, 2025)
XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to remote code execution by parsing untrusted XML payload
Attacker Value
Unknown

CVE-2024-3970

Disclosure Date: May 15, 2024 (last updated January 22, 2025)
Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure by directory traversal.