PT-2022-24282 · Esri · Esri Portal For Arcgis

Published

2022-12-29

·

Updated

2023-01-05

·

CVE-2022-38205

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Esri Portal for ArcGIS versions 10.9.1 and below
Description A directory traversal issue may allow a remote, unauthenticated attacker to traverse the file system, potentially leading to the disclosure of sensitive data. This issue does not affect customer-published content.
Recommendations For Esri Portal for ArcGIS versions 10.9.1 and below, update to a version above 10.9.1 to resolve the issue.

Fix

Path traversal

Relative Path Traversal

Weakness Enumeration

Related Identifiers

CVE-2022-38205

Affected Products

Esri Portal For Arcgis