Impact
The vulnerability is a missing authentication flaw that allows a remote, unauthenticated attacker to read a specific resource that should only be accessible to authenticated users. Because the flaw bypasses normal authorization checks, the attacker can obtain data from a protected endpoint. The weakness corresponds to CWE-306, reflecting a failure to enforce authentication before granting access.
Affected Systems
Esri Portal for ArcGIS is affected. Versions 12.0 and all earlier releases, including ArcGIS Enterprise 11.1, 11.3 and 11.5, are vulnerable. Users running these versions should apply the vendor patch or upgrade to the most recent long‑term support release to address the issue.
Risk and Exploitability
The CVSS base score is 5.3, indicating moderate risk. EPSS data is not available, so the current exploitation probability is unknown but the absence of a certificate does not negate the potential for exploitation. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is network‑based; an attacker can send unauthenticated requests to the exposed resource from the internet or internal network, potentially bypassing any configured authentication controls.
OpenCVE Enrichment