Security Advisory

CVE-2022-38184

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-08-16 17:20:14
Last updated 2025-04-10 14:56:50
Assigner Esri
CVSS score 7.5
State PUBLISHED

Description

There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a remote, unauthenticated attacker to access an API that may induce Esri Portal for ArcGIS to read arbitrary URLs.