Vulnerability Details CVE-2024-38040
There is a local file inclusion vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sensitive configuration information by reading internal files.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 35.2%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2024-38040
-
cpe:2.3:a:esri:portal_for_arcgis:10.9.1
-
cpe:2.3:a:esri:portal_for_arcgis:11.0
-
cpe:2.3:a:esri:portal_for_arcgis:11.1
-
cpe:2.3:a:esri:portal_for_arcgis:11.2