CVE-2022-38208: Unvalidated redirect in Portal for ArcGIS
Published Dec 29, 2022
·Updated
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.
Affected Software
1 affected component
Esri Portal for ArcGIS<=11.0
Event History
Dec 29, 2022
CVE Published
08:15 PM
Dec 30, 2022
CVE Published
via MITRE·05:13 AM
Data Sourced
via MITRE·05:13 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-38208?
CVE-2022-38208 is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11 and below.
2
How does CVE-2022-38208 impact Esri Portal for ArcGIS?
CVE-2022-38208 allows a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.
3
What is the severity of CVE-2022-38208?
CVE-2022-38208 has a severity of medium with a severity score of 6.1.
4
How can I fix CVE-2022-38208 in Esri Portal for ArcGIS?
To fix CVE-2022-38208, users should apply the security update patch provided by Esri. Refer to the official Esri website for more details.