Information Disclosure Vulnerability in Fortinet FortiSIEM Affected by LDAP Password Exposure
CVE-2018-13378
7.2HIGH
What is CVE-2018-13378?
An information disclosure vulnerability exists in Fortinet's FortiSIEM 5.2.0 and earlier versions. This flaw allows unauthorized access to the plaintext password of the LDAP server through the HTML source code, potentially exposing sensitive authentication credentials. Organizations using these versions are urged to assess their security posture and apply necessary mitigations.
Affected Version(s)
Fortinet FortiSIEM FortiSIEM 5.2.0