An improper authentication in Fortinet FortiManager version 6.4.3 and below, 6.2.6 and below allows attacker to assign arbitrary Policy and Object modules via crafted requests to the request handler.
| Software | From | Fixed in |
|---|---|---|
| fortinet / fortimanager | 6.4.0 | 6.4.4 |
| fortinet / fortimanager | - | 6.2.7 |