PT-2022-24271 · Esri · Esri Portal For Arcgis

Published

2022-08-16

·

Updated

2022-08-17

·

CVE-2022-38194

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Esri Portal for ArcGIS version 10.8.1
Description A system property in Esri Portal for ArcGIS is not properly encrypted, potentially allowing a local user to read sensitive information from a properties file.
Recommendations For Esri Portal for ArcGIS version 10.8.1, update the system to properly encrypt sensitive information to prevent unauthorized access.

Fix

Missing Encryption of Sensitive Data

Weakness Enumeration

Related Identifiers

CVE-2022-38194

Affected Products

Esri Portal For Arcgis