CVE-2022-38184: There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1
Published Aug 16, 2022
·Updated
There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a remote, unauthenticated attacker to access an API that may induce Esri Portal for ArcGIS to read arbitrary URLs.
Affected Software
1 affected component
Esri Portal for ArcGIS<=10.8.1
Event History
Aug 16, 2022
CVE Published
via MITRE·05:20 PM
Data Sourced
via MITRE·05:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-38184.
2
What is the severity of CVE-2022-38184?
The severity of CVE-2022-38184 is high with a CVSS score of 7.5.
3
Which versions of Portal for ArcGIS are affected by CVE-2022-38184?
Portal for ArcGIS versions 10.8.1 and below are affected by CVE-2022-38184.
4
What is the impact of CVE-2022-38184?
CVE-2022-38184 could allow a remote, unauthenticated attacker to access an API that may induce Esri Portal for ArcGIS to read arbitrary URLs.
5
How can I mitigate CVE-2022-38184?
To mitigate CVE-2022-38184, apply the security update available from the official Esri Portal for ArcGIS website.