MEDIUM · 5.4

CVE-2023-25834

Changes to user permissions in Portal for ArcGIS 10.9.1 and below are incompletely applied in specific use cases. This issue may allow users to access content that they are no longer privileged to acc...

Vulnerability Description

Changes to user permissions in Portal for ArcGIS 10.9.1 and below are incompletely applied in specific use cases. This issue may allow users to access content that they are no longer privileged to access.

CVSS Score

5.4

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
EsriPortal For Arcgis>= 10.7.1, <= 10.9.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-25834?

CVE-2023-25834 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Changes to user permissions in Portal for ArcGIS 10.9.1 and below are incompletely applied in specific use cases. This issue may allow users to access content that they are no longer privileged to acc...

How severe is CVE-2023-25834?

CVE-2023-25834 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-25834?

Check the references section above for vendor advisories and patch information. Affected products include: Esri Portal For Arcgis.