Vulnerabilities > Esri

DATE CVE VULNERABILITY TITLE RISK
2022-08-16 CVE-2022-38194 Missing Encryption of Sensitive Data vulnerability in Esri Portal for Arcgis 10.8.1
In Esri Portal for ArcGIS versions 10.8.1, a system property is not properly encrypted.
local
low complexity
esri CWE-311
5.5
2022-08-15 CVE-2022-38186 Cross-site Scripting vulnerability in Esri Portal for Arcgis
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below which may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the victim’s browser.
network
low complexity
esri CWE-79
6.1
2022-08-15 CVE-2022-38187 Unspecified vulnerability in Esri Portal for Arcgis
Prior to version 10.9.0, the sharing/rest/content/features/analyze endpoint is always accessible to anonymous users, which could allow an unauthenticated attacker to induce Esri Portal for ArcGIS to read arbitrary URLs.
network
low complexity
esri
7.5
2022-08-15 CVE-2022-38188 Cross-site Scripting vulnerability in Esri Portal for Arcgis
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 which may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the victim’s browser.
network
low complexity
esri CWE-79
6.1
2022-08-15 CVE-2022-38190 Cross-site Scripting vulnerability in Esri Portal for Arcgis
A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS configurable apps may allow a remote, unauthenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the user’s browser
network
low complexity
esri CWE-79
6.1
2022-08-15 CVE-2022-38191 Cross-site Scripting vulnerability in Esri Portal for Arcgis
There is an HTML injection issue in Esri Portal for ArcGIS versions 10.9.0 and below which may allow a remote, authenticated attacker to inject HTML into some locations in the home application.
network
low complexity
esri CWE-79
5.4
2022-08-12 CVE-2021-29112 Out-of-bounds Read vulnerability in Esri Arcreader
An out-of-bounds read vulnerability exists when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) which allow an unauthenticated attacker to induce an information disclosure issue in the context of the current user.
local
low complexity
esri CWE-125
5.5
2022-08-12 CVE-2021-29117 Use After Free vulnerability in Esri Arcreader
A use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) allows an unauthenticated attacker to achieve arbitrary code execution in the context of the current user.
local
low complexity
esri CWE-416
7.8
2022-08-12 CVE-2021-29118 Out-of-bounds Read vulnerability in Esri Arcreader
An out-of-bounds read vulnerability exists when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) which allow an unauthenticated attacker to induce an information disclosure issue in the context of the current user.
local
low complexity
esri CWE-125
5.5
2021-12-07 CVE-2021-29113 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Esri Arcgis Server
A remote file inclusion vulnerability in the ArcGIS Server help documentation may allow a remote, unauthenticated attacker to inject attacker supplied html into a page.
network
low complexity
esri CWE-829
4.7