Show filters
55 Total Results
Displaying 51-55 of 55
Sort by:
Attacker Value
Unknown

CVE-2022-38186

Disclosure Date: June 28, 2022 (last updated February 24, 2025)
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below which may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the victim’s browser.
Attacker Value
Unknown

CVE-2022-38184

Disclosure Date: June 28, 2022 (last updated February 24, 2025)
There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a remote, unauthenticated attacker to access an API that may induce Esri Portal for ArcGIS to read arbitrary URLs.
Attacker Value
Unknown

CVE-2021-29110

Disclosure Date: July 15, 2021 (last updated February 23, 2025)
Stored cross-site scripting (XSS) issue in Esri Portal for ArcGIS may allow a remote unauthenticated attacker to pass and store malicious strings in the home application.
Attacker Value
Unknown

CVE-2021-29109

Disclosure Date: July 15, 2021 (last updated February 23, 2025)
A reflected XSS vulnerability in Esri Portal for ArcGIS version 10.9 and below may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the user’s browser.
Attacker Value
Unknown

CVE-2021-29108

Disclosure Date: July 15, 2021 (last updated February 23, 2025)
There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker who is able to intercept and modify a SAML assertion to impersonate another account (XML Signature Wrapping Attack). In addition patching, Esri also strongly recommends as best practice for SAML assertions to be signed and encrypted.
0