Описание
An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.
Уязвимые конфигурации
Конфигурация 1
Одновременно
Одно из
cpe:2.3:a:esri:portal_for_arcgis:11.4:-:*:*:*:*:*:*
cpe:2.3:a:esri:portal_for_arcgis:11.5:-:*:*:*:*:*:*
cpe:2.3:a:esri:portal_for_arcgis:12.0:-:*:*:*:*:*:*
Одно из
cpe:2.3:a:kubernetes:kubernetes:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
EPSS
Процентиль: 23%
0.00312
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-266
Связанные уязвимости
CVSS3: 9.8
github
3 месяца назад
An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.
EPSS
Процентиль: 23%
0.00312
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-266