Description
There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a remote, unauthenticated attacker to access an API that may induce Esri Portal for ArcGIS to read arbitrary URLs.
No analysis available yet.
Remediation
Vendor Workaround
Disable anonymous access to Portal for ArcGIS.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-40777 | There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a remote, unauthenticated attacker to access an API that may induce Esri Portal for ArcGIS to read arbitrary URLs. |
References
History
Thu, 10 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Esri
Published:
Updated: 2025-04-10T14:56:50.818Z
Reserved: 2022-08-12T00:00:00.000Z
Link: CVE-2022-38184
Updated: 2024-08-03T10:45:52.936Z
Status : Modified
Published: 2022-08-16T18:15:09.277
Modified: 2024-11-21T07:15:57.543
Link: CVE-2022-38184
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD