Vulnerabilities > Esri > Portal FOR Arcgis > High

DATE CVE VULNERABILITY TITLE RISK
2024-10-04 CVE-2024-38040 Unspecified vulnerability in Esri Portal for Arcgis
There is a local file inclusion vulnerability in Esri Portal for ArcGIS 11.2.
network
low complexity
esri
7.5
2023-05-09 CVE-2023-25832 Cross-Site Request Forgery (CSRF) vulnerability in Esri Portal for Arcgis
There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.0 and below that may allow an attacker to trick an authorized user into executing unwanted actions.
network
low complexity
esri CWE-352
8.8
2022-12-29 CVE-2022-38203 Server-Side Request Forgery (SSRF) vulnerability in Esri Portal for Arcgis
Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.8.1 and below were not fully honored and may allow a remote, unauthenticated attacker to forge requests to arbitrary URLs from the system, potentially leading to network enumeration or reading from hosts inside the network perimeter, a different issue than CVE-2022-38211 and CVE-2022-38212.
network
low complexity
esri CWE-918
7.5
2022-12-29 CVE-2022-38211 Server-Side Request Forgery (SSRF) vulnerability in Esri Portal for Arcgis
Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.9.1 and below were not fully honored and may allow a remote, unauthenticated attacker to forge requests to arbitrary URLs from the system, potentially leading to network enumeration or reading from hosts inside the network perimeter, a different issue than CVE-2022-38211 and CVE-2022-38212.
network
low complexity
esri CWE-918
7.5
2022-12-29 CVE-2022-38212 Server-Side Request Forgery (SSRF) vulnerability in Esri Portal for Arcgis
Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.8.1 and below were not fully honored and may allow a remote, unauthenticated attacker to forge requests to arbitrary URLs from the system, potentially leading to network enumeration or reading from hosts inside the network perimeter, a different issue than CVE-2022-38211 and CVE-2022-38203.
network
low complexity
esri CWE-918
7.5
2022-08-16 CVE-2022-38184 Unspecified vulnerability in Esri Portal for Arcgis
There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a remote, unauthenticated attacker to access an API that may induce Esri Portal for ArcGIS to read arbitrary URLs.
network
low complexity
esri
7.5
2021-10-01 CVE-2021-29108 Improper Verification of Cryptographic Signature vulnerability in Esri Portal for Arcgis
There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker who is able to intercept and modify a SAML assertion to impersonate another account (XML Signature Wrapping Attack).
network
low complexity
esri CWE-347
8.8