There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Portal_for_arcgis | Esri | 10.9.1 (including) | 10.9.1 (including) |
| Portal_for_arcgis | Esri | 10.9.1-security_2025_update1 (including) | 10.9.1-security_2025_update1 (including) |
| Portal_for_arcgis | Esri | 10.9.1-security_2025_update2 (including) | 10.9.1-security_2025_update2 (including) |
| Portal_for_arcgis | Esri | 11.0 (including) | 11.0 (including) |
| Portal_for_arcgis | Esri | 11.1 (including) | 11.1 (including) |
| Portal_for_arcgis | Esri | 11.1-security_2024_update1 (including) | 11.1-security_2024_update1 (including) |
| Portal_for_arcgis | Esri | 11.1-security_2024_update2 (including) | 11.1-security_2024_update2 (including) |
| Portal_for_arcgis | Esri | 11.1-security_2025_update1 (including) | 11.1-security_2025_update1 (including) |
| Portal_for_arcgis | Esri | 11.1-security_2025_update2 (including) | 11.1-security_2025_update2 (including) |
| Portal_for_arcgis | Esri | 11.2 (including) | 11.2 (including) |
| Portal_for_arcgis | Esri | 11.2-security_2024_update1 (including) | 11.2-security_2024_update1 (including) |
| Portal_for_arcgis | Esri | 11.2-security_2024_update2 (including) | 11.2-security_2024_update2 (including) |
| Portal_for_arcgis | Esri | 11.2-security_2025_update1 (including) | 11.2-security_2025_update1 (including) |
| Portal_for_arcgis | Esri | 11.2-security_2025_update2 (including) | 11.2-security_2025_update2 (including) |
| Portal_for_arcgis | Esri | 11.3 (including) | 11.3 (including) |
| Portal_for_arcgis | Esri | 11.3-security_2025_update1 (including) | 11.3-security_2025_update1 (including) |
| Portal_for_arcgis | Esri | 11.3-security_2025_update2 (including) | 11.3-security_2025_update2 (including) |
| Portal_for_arcgis | Esri | 11.4 (including) | 11.4 (including) |
| Portal_for_arcgis | Esri | 11.4-security_2025_update1 (including) | 11.4-security_2025_update1 (including) |
| Portal_for_arcgis | Esri | 11.4-security_2025_update2 (including) | 11.4-security_2025_update2 (including) |