VendorsEsriarcgis_enterpriseall versions
Vulnerabilities

Esri Arcgis Enterprise

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2024-25699
Portal for ArcGIS has an invalid authentication vulnerability
Published 2024-04-04 · Analyzed
8.5EPSS 0.007
CVE-2021-3012
A cross-site scripting (XSS) vulnerability in the Document Link of documents in ESRI Enterprise before 10.9 allows remote authenticated users to inject arbitrary JavaScript code via a malicious HTML attribute such as onerror (in the URL field of the Parameters tab).
Published 2021-04-08 · Modified
5.4EPSS 0.007
CVE-2019-16193
In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack through the EDIT MY PROFILE feature.
Published 2019-09-11 · Modified
5.4EPSS 0.006
CVE-2021-29115
An information disclosure vulnerability
Published 2021-12-07 · Modified
5.3EPSS 0.022
CVE-2024-25708
Persistent XSS when creating new application using Web App Builder
Published 2024-04-04 · Modified
4.8EPSS 0.004