A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSRA 1.4.0 through 1.4.1 allows attacker to improper access control via specially crafted HTTP requests
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-25-008 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2025-06-10 17:21
Updated : 2025-07-24 19:58
NVD link : CVE-2025-22256
Mitre link : CVE-2025-22256
CVE.ORG link : CVE-2025-22256
JSON object : View
Products Affected
fortinet
- fortisra
- fortipam
CWE
CWE-280
Improper Handling of Insufficient Permissions or Privileges
