VDOM separation flawed?
I've seen long time ago and even now with newer versions of FortiOS that when managing one VDOM, I can actually see important information about other VDOMs in CLI. I just rechecked it in a device with 6.2.10 where I have been given access to one VDOM only as a tenant that yes, I can see the names of other clients using the same device, some other important IP-addresses of theirs and possibly more if I would want. It's the same with 6.4.4.
At the same time, I can read from the documentation: "VDOM administrators will be unable to view global settings or VDOMs not assigned to them because the scope of their role is restricted to managing specific VDOMs only. An example of a VDOM administrator is the administrator working for a company which is a client, or tenant, of an MSSP’s multi-tenant FortiGate."
Well, getting the list of names of all clients isn't really separating, is it? Should I write down those few commands that show this information that I've tried so far? They are nothing special, typical commands for CLI. Or is it a public secret that VDOMs are not really separated so tenants can see information about other tenants? Because, as I said, I've seen this already ~5 years ago and they are still there behaving the same way today.
