PT-2022-24285 · Esri · Esri Portal For Arcgis

Published

2022-12-29

·

Updated

2023-01-05

·

CVE-2022-38208

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Esri Portal for ArcGIS versions 11 and below
Description The issue allows a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks. This is due to an unvalidated redirect vulnerability.
Recommendations For Esri Portal for ArcGIS versions 11 and below, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2022-38208

Affected Products

Esri Portal For Arcgis