Home
HIGH: 8.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:U/RC:CDefault status
unaffected
6.4.0 (semver)
affected
6.3.0 (semver)
affected
6.2.0 (semver)
affected
6.1.0 (semver)
affected
6.0.0 (semver)
affected
5.9.0 (semver)
affected
5.8.5 (semver)
affected
5.8.0 (semver)
affected
5.7.0 (semver)
affected
5.6.0 (semver)
affected
Description
A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 through 6.0.7, 5.9.0 through 5.9.1 may allow a remote, unauthenticated attacker to infer the session identifier of other users and possibly usurp their session.
Problem types
Product status
6.4.0 (semver)
6.3.0 (semver)
6.2.0 (semver)
6.1.0 (semver)
6.0.0 (semver)
5.9.0 (semver)
5.8.5 (semver)
5.8.0 (semver)
5.7.0 (semver)
5.6.0 (semver)
References
fortiguard.com/psirt/FG-IR-21-214
fortiguard.com/psirt/FG-IR-21-214