Esri Portal for ArcGIS
cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*
- <= 11.4
A vulnerability allowing unvalidated redirects has been identified in Esri Portal for ArcGIS versions 11.4 and prior. This issue may enable a remote, unauthenticated attacker to create a URL that redirects a victim to an arbitrary website, potentially facilitating phishing attacks.
Exploitation of this vulnerability could lead to successful phishing attempts, as victims could be redirected to malicious websites.
Esri has released a security patch for Portal for ArcGIS in 2025 Update 3. This patch addresses this vulnerability and is available for download. Instructions for applying the patch can be found on the Esri Support website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.