Description | This article discusses JAZZ-187: Unprotected Jazz Agent data on the first run. |
Scope | FortiDLP. |
Solution |
Release Date: 17th June, 2019
Overview: Directories containing Jazz Agent data were found to be unprotected on the first run of the Jazz Agent. This could allow an attacker to modify data sent to the Jazz Infrastructure.
Affected Products:
Unaffected Products:
Resolution: This issue is fixed in Jazz Agent 4.0.0.
It is strongly recommended that all customers ensure the Jazz Agent has been restarted after the first installation on all nodes. An upgrade to Jazz Agent 4.0.0 will also fix this issue.
Vulnerability Information: JAZZ-187 allows an unprivileged user to read and modify the data sent by the Jazz Agent to the Jazz Infrastructure if the Agent has not been restarted since installation. It would not be possible to read or modify data already present in the Jazz Infrastructure.
Acknowledgments: Issue found internally by Jazz Networks.
Disclosure Timeline:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.