First published: Thu Apr 04 2024(Updated: )
There is a difficult to exploit improper authentication issue in the Home application for Esri Portal for ArcGIS versions 10.8.1 through 11.2 on Windows and Linux, and ArcGIS Enterprise 11.1 and below on Kubernetes which, under unique circumstances, could potentially allow a remote, unauthenticated attacker to compromise the confidentiality, integrity, and availability of the software.
Credit: psirt@esri.com
Affected Software | Affected Version | How to fix |
---|---|---|
Esri Portal for ArcGIS | >=10.8.1<=11.2 | |
Esri ArcGIS Enterprise | <11.1 | |
All of | ||
Esri Portal for ArcGIS | >=10.8.1<=11.2 | |
Any of | ||
Linux Kernel | ||
Microsoft Windows | ||
Esri ArcGIS Enterprise | <=11.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-25699 is considered high due to the potential for improper authentication that could be exploited remotely.
To fix CVE-2024-25699, update the Esri Portal for ArcGIS to version 11.2 or higher or ArcGIS Enterprise to version 11.2 or above.
CVE-2024-25699 affects Esri Portal for ArcGIS versions 10.8.1 through 11.2 and ArcGIS Enterprise version 11.1 and below.
CVE-2024-25699 is classified as a remote vulnerability that can be exploited under specific conditions.
CVE-2024-25699 is an improper authentication issue that could allow unauthorized access to the Home application in affected software.