Back

CVE-2015-3616

CRITICAL

SQL injection vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to execute arbitrary commands via unspecified parameters.

Published: Aug 11, 2017 Modified: Jun 17, 2026
CWE-89

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (13)

Vendor Product Version
fortinet fortimanager_firmware 5.0.0
fortinet fortimanager_firmware 5.0.1
fortinet fortimanager_firmware 5.0.2
fortinet fortimanager_firmware 5.0.3
fortinet fortimanager_firmware 5.0.4
fortinet fortimanager_firmware 5.0.5
fortinet fortimanager_firmware 5.0.6
fortinet fortimanager_firmware 5.0.7
fortinet fortimanager_firmware 5.0.8
fortinet fortimanager_firmware 5.0.9
fortinet fortimanager_firmware 5.0.10
fortinet fortimanager_firmware 5.2.0
fortinet fortimanager_firmware 5.2.1

GitHub Security Advisory GHSA-pjc2-fghh-wx28

SQL injection vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 2.34%

Top 18% most likely to be exploited

Threat Score 39.9 / 100

Data Sources

NVD EPSS GitHub