Esri Portal for ArcGIS
cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*
- <= 11.4
A server-side request forgery (SSRF) vulnerability has been identified in Esri Portal for ArcGIS versions through 11.4. This vulnerability allows remote, unauthenticated attackers to bypass the application's SSRF protections.
Exploitation of this vulnerability could lead to unauthorized access to internal services or resources, allowing attackers to manipulate requests on behalf of the server.
Users can apply the Portal for ArcGIS Security 2025 Update 2 Patch, available through the Esri Support website. It is recommended to upgrade to version 11.5 or greater, and for those using versions in Mature or Retired status, to plan an upgrade to a General Availability release version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.