Esri Portal for ArcGIS 11.4 and prior allows a remote, unauthenticated attacker to bypass the Portal’s SSRF protections.
Metrics
Affected Vendors & Products
References
History
Mon, 15 Dec 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 15 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 30 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*:* |
Thu, 29 May 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 29 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Esri Portal for ArcGIS 11.4 and prior allows a remote, unauthenticated attacker to bypass the Portal’s SSRF protections. | |
| Title | Server Side Request Forgery (SSRF) vulnerability in Portal for ArcGIS | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Esri
Published: 2025-05-29T19:58:47.947Z
Updated: 2025-12-15T20:01:45.607Z
Reserved: 2025-05-19T20:42:42.569Z
Link: CVE-2025-4967
Updated: 2025-05-29T20:17:34.910Z
Status : Modified
Published: 2025-05-29T20:15:27.660
Modified: 2025-12-15T20:15:51.473
Link: CVE-2025-4967
No data.