VendorsEsriportal_for_arcgis10.8.1
Vulnerabilities

Esri Portal 10.8.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2022-38194
Portal for ArcGIS system properties are not properly encrypted (10.8.1 only)
Published 2022-08-16 · Modified
6.7EPSS 0.001
CVE-2023-25831
BUG-000154236 There is a reflected cross-site scripting (XSS) vulnerability in Portal for ArcGIS.
Published 2023-05-09 · Analyzed
6.1EPSS 0.005
CVE-2023-25830
BUG-000154662 Reflected XSS vulnerability in Portal for ArcGIS
Published 2023-05-09 · Analyzed
6.1EPSS 0.005
CVE-2022-38204
Reflected XSS vulnerability in Portal for ArcGIS (10.8.1 and 10.7.1 only)
Published 2022-12-30 · Modified
6.1EPSS 0.005
CVE-2022-38207
Reflected XSS vulnerability in Portal for ArcGIS (10.8.1 and 10.7.1 only)
Published 2022-12-30 · Modified
6.1EPSS 0.005
CVE-2024-25709
Self-XSS style in move item dialog
Published 2024-04-04 · Analyzed
6.1EPSS 0.004
CVE-2024-25691
BUG-000165286 - Reflected XSS in Portal for ArcGIS
Published 2024-10-04 · Modified
6.1EPSS 0.003
CVE-2024-38038
BUG-000165732 - Reflected XSS in Portal for ArcGIS
Published 2024-10-04 · Modified
6.1EPSS 0.003
CVE-2024-8148
BUG-000168624 - Unvalidated redirect in Portal for ArcGIS. (11.2, 11.1, 10.9.1. and 10.8.1)
Published 2024-10-04 · Modified
6.1EPSS 0.003
CVE-2024-38036
BUG-000154827 - Reflected XSS in ArcGIS Experience Builder
Published 2024-10-04 · Modified
5.4EPSS 0.006