PT-2025-23199 · Esri · Esri Portal For Arcgis

Published

2025-05-28

·

Updated

2025-12-15

·

CVE-2025-4967

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Esri Portal for ArcGIS versions 11.4 and prior
Description The issue allows a remote, unauthenticated attacker to bypass the Portal’s Server Side Request Forgery (SSRF) protections. This enables the attacker to potentially exploit the system.
Recommendations For Esri Portal for ArcGIS versions 11.4 and prior, update to a version that includes the security patch for this issue, as provided in the 2025 update 2 patch.

Fix

SSRF

Weakness Enumeration

Related Identifiers

BDU:2025-13109
CVE-2025-4967

Affected Products

Esri Portal For Arcgis