A hardcoded credential vulnerability exists in a specific deployment pattern for Esri Portal for ArcGIS versions 11.4 and below that may allow a remote unauthenticated attacker to gain administrative access to the system.
References
| Link | Resource |
|---|---|
| https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/portal-for-arcgis-security-2025-update-1-patch/ | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2025-03-20 21:15
Updated : 2025-07-30 20:01
NVD link : CVE-2025-2538
Mitre link : CVE-2025-2538
CVE.ORG link : CVE-2025-2538
JSON object : View
Products Affected
esri
- portal_for_arcgis
CWE
CWE-798
Use of Hard-coded Credentials
