Fortinet Fortianalyzer-Bigdata vulnerabilities
4 known vulnerabilities affecting fortinet/fortianalyzer-bigdata.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2025-61848P3HIGHCVSS 7.2≥ 7.6.0, ≤ 7.6.12026-04-14
CVE-2025-61848 [HIGH] CWE-89 CVE-2025-61848: An improper neutralization of special elements used in an sql command ('sql injection') vulnerabilit
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.2 through 7.6.3, FortiAnalyzer-BigData 7.6.0 through 7.6.1, FortiAnalyzer-BigData
nvd
CVE-2025-49784P3HIGHCVSS 7.2v7.6.02026-03-10
CVE-2025-49784 [HIGH] CWE-89 CVE-2025-49784: An improper neutralization of special elements used in an sql command ('sql injection') vulnerabilit
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer-BigData 7.6.0, FortiAnalyzer-BigData 7.4.0 through 7.4.4, Fo
nvd
CVE-2023-42787P3MEDIUMCVSS 6.5≥ 7.2.0, ≤ 7.2.5≥ 7.0.1, ≤ 7.0.6+2 more2023-10-10
CVE-2023-42787 [MEDIUM] CWE-602 CVE-2023-42787: A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager v
A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access a privileged web console via client side code execution.
nvd
CVE-2023-41842P4MEDIUMCVSS 6.7≥ 7.2.0, ≤ 7.2.5≥ 7.0.1, ≤ 7.0.6+2 more2024-03-12
CVE-2023-41842 [MEDIUM] CWE-134 CVE-2023-41842: A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allo
A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute unauthorized code or commands via specially crafted command arguments.
nvd