CVE-2025-4967: Server Side Request Forgery (SSRF) vulnerability in Portal for ArcGIS
Published May 29, 2025
·Updated
Esri Portal for ArcGIS 11.4 and prior allows a remote, unauthenticated attacker to bypass the Portal’s SSRF protections.
Affected Software
2 affected components
Esri Portal for ArcGIS<11.4
Esri Portal for ArcGIS<=11.4
Event History
May 29, 2025
CVE Published
via MITRE·07:58 PM
Data Sourced
via MITRE·07:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-4967?
CVE-2025-4967 has been assigned a high severity rating due to its potential for exploitation by unauthenticated attackers.
2
How do I fix CVE-2025-4967?
To remediate CVE-2025-4967, upgrade to Esri Portal for ArcGIS version 11.4 or later.
3
What types of attacks can CVE-2025-4967 facilitate?
CVE-2025-4967 can allow remote unauthenticated attackers to bypass Server-Side Request Forgery (SSRF) protections.
4
Is CVE-2025-4967 applicable to earlier versions of Esri Portal for ArcGIS?
Yes, CVE-2025-4967 affects all versions of Esri Portal for ArcGIS prior to 11.4.
5
What environments are at risk from CVE-2025-4967?
Environments running Esri Portal for ArcGIS 11.4 and earlier are at risk from CVE-2025-4967 vulnerabilities.