Esri Portal for ArcGIS
cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*
- <= 11.4
A vulnerability allowing unvalidated redirects has been identified in Esri Portal for ArcGIS versions 11.4 and prior. This issue may enable a remote, unauthenticated attacker to create a URL that redirects a victim to an arbitrary website, potentially facilitating phishing attacks.
Exploitation of this vulnerability could lead to successful phishing attempts, as victims could be redirected to malicious websites.
Esri has released a security patch for this vulnerability as part of the Portal for ArcGIS Security 2025 Update 3 Patch. This patch is cumulative and includes all fixes from previous updates. Instructions for applying the patch are available on the Esri Support website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.