Description | This article discusses JAZZ-213: Raising a large number of Sensors causes API errors |
Scope | FortiDLP. |
Solution |
Release Date: 10 July 2019.
Overview: Data for entities with a large number of alarms and sensors will be unavailable via the API. This affects endpoints returning entity metadata and event data of all types, and can therefore impede investigation of an entity.
Affected Products: The following products or components have been identified as affected by this vulnerability:
Unaffected Products: The following products or components are unaffected:
Resolution: This issue has been fixed in Jazz Infrastructure version 5.0.3.
It is strongly recommended that all On-Premises installations running an affected version upgrade to the latest release as soon as possible. Releases are available to download through the Jazz Networks support portal.
A mitigation was deployed to the Jazz Cloud on 8 July 2019. Jazz Cloud customers do not need to take any additional action.
Vulnerability Information: API endpoints that return alarm data will return an HTTP 429 error if the alarms contain a large number of sensors. An attacker with access to a machine running the Jazz Agent is able to trigger an arbitrary number of sensors and can therefore deny access to data.
Affected endpoints are: api/v1/alarms/log/riskquery, api/v1/nodes/<id>, api/v1/user/<id>
Acknowledgments: Issue found internally by Jazz Networks.
Disclosure Timeline:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.