Vulnerability Details CVE-2022-38184
There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a remote, unauthenticated attacker to access an API that may induce Esri Portal for ArcGIS to read arbitrary URLs.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 65.9%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2022-38184
-
cpe:2.3:a:esri:portal_for_arcgis:-
-
cpe:2.3:a:esri:portal_for_arcgis:10.6
-
cpe:2.3:a:esri:portal_for_arcgis:10.6.1
-
cpe:2.3:a:esri:portal_for_arcgis:10.7.1
-
cpe:2.3:a:esri:portal_for_arcgis:10.8
-
cpe:2.3:a:esri:portal_for_arcgis:10.8.1