First published: Tue Aug 16 2022(Updated: )
There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a remote, unauthenticated attacker to access an API that may induce Esri Portal for ArcGIS to read arbitrary URLs.
Credit: psirt@esri.com
Affected Software | Affected Version | How to fix |
---|---|---|
Esri Portal for ArcGIS | <=10.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-38184.
The severity of CVE-2022-38184 is high with a CVSS score of 7.5.
Portal for ArcGIS versions 10.8.1 and below are affected by CVE-2022-38184.
CVE-2022-38184 could allow a remote, unauthenticated attacker to access an API that may induce Esri Portal for ArcGIS to read arbitrary URLs.
To mitigate CVE-2022-38184, apply the security update available from the official Esri Portal for ArcGIS website.