There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker to impersonate another account.
References
Configurations
Information
Published : 2021-10-01 15:15
Updated : 2022-02-28 17:15
NVD link : CVE-2021-29108
Mitre link : CVE-2021-29108
JSON object : View
Products Affected
esri
- portal_for_arcgis
CWE
CWE-269
Improper Privilege Management
