First published: Tue Aug 16 2022(Updated: )
In Esri Portal for ArcGIS versions 10.8.1, a system property is not properly encrypted. This may lead to a local user reading sensitive information from a properties file.
Credit: psirt@esri.com
Affected Software | Affected Version | How to fix |
---|---|---|
Esri Portal for ArcGIS | =10.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38194 is a vulnerability in Esri Portal for ArcGIS version 10.8.1, where a system property is not properly encrypted, allowing a local user to read sensitive information from a properties file.
CVE-2022-38194 has a severity rating of 5.5 (medium).
CVE-2022-38194 can be exploited by a local user to read sensitive information from a properties file.
Yes, a patch for CVE-2022-38194 is available. Please refer to the following link for more information: [Link to the patch](https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/portal-for-arcgis-security-2022-update-1-patch/)
The CWE ID for CVE-2022-38194 is CWE-311.