7.5
CVSSv3

CVE-2022-38187

Published: 15/08/2022 Updated: 16/08/2022
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Prior to version 10.9.0, the sharing/rest/content/features/analyze endpoint is always accessible to anonymous users, which could allow an unauthenticated malicious user to induce Esri Portal for ArcGIS to read arbitrary URLs.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

esri portal for arcgis