CVE-2022-38194: Portal for ArcGIS system properties are not properly encrypted (10.8.1 only)
In Esri Portal for ArcGIS versions 10.8.1, a system property is not properly encrypted. This may lead to a local user reading sensitive information from a properties file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-38194?
CVE-2022-38194 is a vulnerability in Esri Portal for ArcGIS version 10.8.1, where a system property is not properly encrypted, allowing a local user to read sensitive information from a properties file.
How severe is CVE-2022-38194?
CVE-2022-38194 has a severity rating of 5.5 (medium).
How can CVE-2022-38194 be exploited?
CVE-2022-38194 can be exploited by a local user to read sensitive information from a properties file.
Is there a patch or update available for CVE-2022-38194?
Yes, a patch for CVE-2022-38194 is available. Please refer to the following link for more information: [Link to the patch](https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/portal-for-arcgis-security-2022-update-1-patch/)
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-38194?
The CWE ID for CVE-2022-38194 is CWE-311.