Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:


Table of Contents

Resolved Issues

The following issues have been fixed in FortiAnalyzer version 6.4.2. For inquires about a particular bug, please contact Customer Service & Support.

Device Manager

Bug ID

Description

641490 FortiAnalyzer may fail to update HA group name after the group name is changed on the FortiGate side causing it crash occasionally.
648893 Device list may be empty in Device Manager after upgrade.

FortiView

Bug ID

Description

590775 FortiAnalyzer should hide Device and Time Frame selection in FortiView Threat Map.
624856 Default user filter is missing from FortiView > VPN > SSL & Dialup IPsec in filter mode while it is available in text mode.
632532 Drill-down in FortiView does not display correctly when log is at the bottom of the display.
641616 Exporting chart from FortiView triggers both successful and error messages.
641983 Traffic filter by policy ID with greater or less than option is not working correctly when viewing real-time logs.

Log View

Bug ID

Description

636967 After upgrade, FortiAnalyzer reports problem that filter in real-time log does not work resulting in No entry found.
642960 Logs imported in Log Browse may not show up in traffic logs.

Others

Bug ID Description
630900 FortiAnalyzer should add filters from session-view to default skip-index list.
645965 The diagnose dvm device list command shows incorrect VDOM to ADOM assignment and Fabric view Asset displays data belonging to different ADOMs.
647589 EMS sysinfo wildcard call should be {'uid_list': []} instead of {'uid_list': ['']}.

644232

FortiAnalyzer may use high IO usage on VACUUM process.

652541 The siemagentd may hang under load.

Reports

Bug ID

Description

296148 FortiAnalyzer needs to restrict log tables when creating a view for dataset testing.
528395 Deleting device from Device Manager removes the report filter but does not stop schedule and notifications.
643238 User should be able filter reports based on device name in Reports > Report Definitions > All Reports.

System Settings

Bug ID Description
599771 When logging in with an LDAP admin, one invalid ADOM value may cause 'authentication failed'.
613032 Cover page files may be not synchronized to secondary unit.
642459 Syslogd receives empty logs when FortiAnalyzer forwards FortiExtender logs.
644863 When SAML uses Supper_User under root ADOM, the user is not able to view analytic logs under FortiView and Event handler prompts "Web Server Error 500".

Common Vulnerabilities and Exposures

Visit https://fortiguard.com/psirt for more information.

Bug ID CVE references

626913

FortiAnalyzer 6.4.2 is no longer vulnerable to the following CVE-Reference:

  • CVE-2020-12817

Resolved Issues

The following issues have been fixed in FortiAnalyzer version 6.4.2. For inquires about a particular bug, please contact Customer Service & Support.

Device Manager

Bug ID

Description

641490 FortiAnalyzer may fail to update HA group name after the group name is changed on the FortiGate side causing it crash occasionally.
648893 Device list may be empty in Device Manager after upgrade.

FortiView

Bug ID

Description

590775 FortiAnalyzer should hide Device and Time Frame selection in FortiView Threat Map.
624856 Default user filter is missing from FortiView > VPN > SSL & Dialup IPsec in filter mode while it is available in text mode.
632532 Drill-down in FortiView does not display correctly when log is at the bottom of the display.
641616 Exporting chart from FortiView triggers both successful and error messages.
641983 Traffic filter by policy ID with greater or less than option is not working correctly when viewing real-time logs.

Log View

Bug ID

Description

636967 After upgrade, FortiAnalyzer reports problem that filter in real-time log does not work resulting in No entry found.
642960 Logs imported in Log Browse may not show up in traffic logs.

Others

Bug ID Description
630900 FortiAnalyzer should add filters from session-view to default skip-index list.
645965 The diagnose dvm device list command shows incorrect VDOM to ADOM assignment and Fabric view Asset displays data belonging to different ADOMs.
647589 EMS sysinfo wildcard call should be {'uid_list': []} instead of {'uid_list': ['']}.

644232

FortiAnalyzer may use high IO usage on VACUUM process.

652541 The siemagentd may hang under load.

Reports

Bug ID

Description

296148 FortiAnalyzer needs to restrict log tables when creating a view for dataset testing.
528395 Deleting device from Device Manager removes the report filter but does not stop schedule and notifications.
643238 User should be able filter reports based on device name in Reports > Report Definitions > All Reports.

System Settings

Bug ID Description
599771 When logging in with an LDAP admin, one invalid ADOM value may cause 'authentication failed'.
613032 Cover page files may be not synchronized to secondary unit.
642459 Syslogd receives empty logs when FortiAnalyzer forwards FortiExtender logs.
644863 When SAML uses Supper_User under root ADOM, the user is not able to view analytic logs under FortiView and Event handler prompts "Web Server Error 500".

Common Vulnerabilities and Exposures

Visit https://fortiguard.com/psirt for more information.

Bug ID CVE references

626913

FortiAnalyzer 6.4.2 is no longer vulnerable to the following CVE-Reference:

  • CVE-2020-12817