Portal for arcgis Vulnerabilities

Security vulnerability tracking for Esri Portal for arcgis

Last updated: Apr 4, 2024
Total CVEs

5

Critical

0

With Exploits

3

Last 30 Days

0

Vulnerability Timeline

5 vulnerabilities discovered over time for Portal for arcgis

Severity Distribution

Critical0
0%
High3
60%
Medium2
40%
Low0
0%
DescriptionVendor / ProductExploit Status
CVE-2024-257096.1

An attacker can create a malicious link that, when saved by a user in Esri Portal for ArcGIS, can run harmful JavaScript code in that user's web browser. This can be done by anyone, even without special permissions, as long as they are logged in to the system.

esriportal for arcgis
Theoretical
almost 2 years agoApr 4, 2024
CVE-2024-257055.4

This vulnerability allows an attacker with basic access to create a malicious link that, when clicked by a user, can run harmful JavaScript code in their browser. The attacker only needs to be logged in with low-level permissions, making it relatively easy to exploit.

esriportal for arcgis
Exploit Available
almost 2 years agoApr 4, 2024
CVE-2024-256998.5

This vulnerability allows a remote attacker with low-level access to gain unauthorized control over parts of the Esri Portal for ArcGIS software, potentially compromising sensitive data and system operations. It can be exploited under specific conditions, making it difficult but still possible for attackers to bypass security boundaries.

esriportal for arcgis
Exploit Available
almost 2 years agoApr 4, 2024
CVE-2023-258378.4

This vulnerability allows an attacker with high-level access to create a malicious link that, when clicked by a victim, can run harmful JavaScript in their browser. This could let the attacker steal sensitive information, alter trusted content, or disrupt the application's normal operations.

esriportal for arcgis
Exploit Available
over 2 years agoJul 21, 2023
CVE-2023-258358.4

This vulnerability allows an attacker with high-level access to create a malicious link that, when clicked by another user, can run harmful JavaScript in their browser. This could let the attacker steal sensitive information, change site content, or disrupt the site’s normal operations, but it requires the attacker to already have elevated privileges within the system.

esriportal for arcgis
Theoretical
over 2 years agoJul 21, 2023

About Esri Portal for arcgis Security

This page provides comprehensive security vulnerability tracking for Esri Portal for arcgis. Our database includes all CVEs affecting this product, updated in real-time from official sources.

Each vulnerability listing includes detailed CVSS severity analysis, exploit availability status, AI-generated explanations, and direct links to official security patches and vendor advisories.

Security Recommendations

  • • Always keep Portal for arcgis updated to the latest version
  • • Subscribe to security advisories from Esri
  • • Monitor this page for new vulnerabilities affecting your version
  • • Prioritize patching critical and high severity issues immediately