PT-2022-24274 · Esri · Esri Arcgis Server

Published

2022-10-25

·

Updated

2022-10-31

·

CVE-2022-38197

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Esri ArcGIS Server versions 10.9.1 and below
Description The issue is related to an unvalidated redirect that may allow a remote, unauthenticated attacker to phish a user into accessing an attacker-controlled website via a crafted query parameter.
Recommendations For Esri ArcGIS Server versions 10.9.1 and below, update to a version above 10.9.1 to resolve the issue. At the moment, there is no information about other specific mitigation measures for this issue.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2022-38197

Affected Products

Esri Arcgis Server