Unvalidated redirect in Portal for ArcGIS
CVE-2022-38208
6.1MEDIUM
What is CVE-2022-38208?
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.
Affected Version(s)
ArcGIS Enterprise x64 Portal for ArcGIS <= 11.0