CVE-2022-26119

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
02/11/2022
Last modified:
08/08/2023

Description

A improper authentication vulnerability in Fortinet FortiSIEM before 6.5.0 allows a local attacker with CLI access to perform operations on the Glassfish server directly via a hardcoded password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:* 5.1.0 (including) 5.1.3 (including)
cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:* 5.2.5 (including) 5.2.8 (including)
cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:* 5.3.0 (including) 5.3.3 (including)
cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:* 6.1.0 (including) 6.1.2 (including)
cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:* 6.3.0 (including) 6.3.3 (including)
cpe:2.3:a:fortinet:fortisiem:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:5.2.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:5.2.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:5.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.2.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.2.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.4.1:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools