PT-2022-24274 · Esri · Esri Arcgis Server

CVE-2022-38197

·

Published

2022-10-25

·

Updated

2022-10-31

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Esri ArcGIS Server versions 10.9.1 and below
Description The issue is related to an unvalidated redirect that may allow a remote, unauthenticated attacker to phish a user into accessing an attacker-controlled website via a crafted query parameter.
Recommendations For Esri ArcGIS Server versions 10.9.1 and below, update to a version above 10.9.1 to resolve the issue. At the moment, there is no information about other specific mitigation measures for this issue.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-38197

Affected Products

Esri Arcgis Server