CVE-2021-36189
published 2021-12-09CVE-2021-36189: A missing encryption of sensitive data in Fortinet FortiClientEMS version 7.0.1 and below, version 6.4.4 and below allows attacker to information disclosure…
PriorityP421medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
EPSS
0.39%
31.3th percentile
A missing encryption of sensitive data in Fortinet FortiClientEMS version 7.0.1 and below, version 6.4.4 and below allows attacker to information disclosure via inspecting browser decrypted data
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlient_enterprise_management_server | — | — |
| fortinet | forticlient_enterprise_management_server | — | — |
| fortinet | forticlient_enterprise_management_server | — | — |
| fortinet | forticlient_enterprise_management_server | 6.4.0 – 6.4.4 | — |
| fortinet | forticlientems | — | — |
| fortinet | forticliententerprisemanagementserver | — | — |
| fortinet | fortinet | — | — |
| fortinet | fortinet_forticlientems | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_oracle8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
A missing encryption of sensitive data in Fortinet FortiClientEMS version 7.0.1 and below, version 6.4.4 and below allow...
vendor_fortinet·2021-12-09·CVSS 6.8
CVE-2021-36189 [MEDIUM] CWE-311 A missing encryption of sensitive data in Fortinet FortiClientEMS version 7.0.1 and below, version 6.4.4 and below allow...
FG-IR-21-140: A missing encryption of sensitive data in Fortinet FortiClientEMS version 7.0.1 and below, version 6.4.4 and below allow...
A missing encryption of sensitive data in Fortinet FortiClientEMS version 7.0.1 and below, version 6.4.4 and below allows attacker to information disclosure via inspecting browser decrypted data
CVEs: CVE-2021-36189
CWEs: CWE-311
CVSS: 6.8 (medium)
Affected products: FortiClientEMS, FortiCliententerprisemanagementserver, Fortinet
Oracle
Oracle Oracle Insurance Applications Risk Matrix: Development tools (jackson-databind) — CVE-2020-36189
vendor_oracle·2021-10-15·CVSS 8.1
CVE-2020-36189 [HIGH] Oracle Oracle Insurance Applications Risk Matrix: Development tools (jackson-databind) — CVE-2020-36189
Oracle Oracle Insurance Applications Risk Matrix: Development tools (jackson-databind) vulnerability
CVE: CVE-2020-36189
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
GHSA
GHSA-v99f-7jp8-w888: A missing encryption of sensitive data in Fortinet FortiClientEMS version 7
ghsa_unreviewed·2021-12-10
CVE-2021-36189 [MEDIUM] CWE-311 GHSA-v99f-7jp8-w888: A missing encryption of sensitive data in Fortinet FortiClientEMS version 7
A missing encryption of sensitive data in Fortinet FortiClientEMS version 7.0.1 and below, version 6.4.4 and below allows attacker to information disclosure via inspecting browser decrypted data
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-12-09
Published