A use of hard-coded credentials (CWE-798) vulnerability in FortiPortal versions 5.2.5 and below, 5.3.5 and below, 6.0.4 and below, versions 5.1.x and 5.0.x may allow a remote and unauthenticated attacker to execute unauthorized commands as root by uploading and deploying malicious web application archive files using the default hard-coded Tomcat Manager username and password.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HFortinet Fortiportal
APPFortinet5.0.0 – 5.0.35.1.0 – 5.1.25.2.0 – 5.2.55.3.0 – 5.3.56.0.0 – 6.0.4
Related vulnerabilities
SQL Injection w Fortinet FortiPortal umożliwiający wykonanie dowolnych poleceń na bazie danych
Słaby mechanizm odzyskiwania hasła w Fortinet FortiPortal umożliwia nieautoryzowane wykonanie kodu
Nieprawidłowa kontrola dostępu w Fortinet FortiPortal — dostęp do nieautoryzowanych VDOM/ADOM
An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 th...
A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7...