CVE-2022-38193

There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass strings which could potentially cause arbitrary code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-08-16 17:15

Updated : 2023-02-10 15:45


NVD link : CVE-2022-38193

Mitre link : CVE-2022-38193

CVE.ORG link : CVE-2022-38193


JSON object : View

Products Affected

esri

  • portal_for_arcgis
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-95

Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')