Impact
A remote, unauthenticated attacker can trigger Esri Portal for ArcGIS to return sensitive information in an HTTP response body. The vulnerability allows the attacker to read data that should be protected, potentially exposing confidential configuration, credentials, or user data. The impact is purely informational, with no direct code execution or denial of service described.
Affected Systems
Esri Portal for ArcGIS versions 11.5 through 12.0 and all earlier releases are susceptible. The vulnerability was identified in the product but not within newer releases beyond 12.0.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting a lower known exploitation likelihood. The likely attack vector is remote and unauthenticated, as the flaw is triggered by general HTTP requests to the portal. No specific conditions such as privilege escalation or special access are required beyond the ability to send a request to the vulnerable instance.
OpenCVE Enrichment