Access Control Vulnerability in Fortinet FortiPAM and FortiSRA Products
CVE-2025-22256
6MEDIUM
What is CVE-2025-22256?
An improper access control vulnerability exists in Fortinet's FortiPAM and FortiSRA products across multiple versions. Attackers can exploit this flaw by sending specially crafted HTTP requests that may allow unauthorized access to sensitive areas of the system, potentially compromising data integrity and confidentiality.
Affected Version(s)
FortiPAM 1.4.0 <= 1.4.1
FortiPAM 1.3.0
FortiPAM 1.2.0