CVE-2025-2538 | Esri Portal for ArcGIS 10.9.1/11.1/11.2/11.3/11.4 Password Recovery hard-coded credentials
A vulnerability, which was classified as critical, was found in Esri Portal for ArcGIS 10.9.1/11.1/11.2/11.3/11.4. This affects an unknown part of the component Password Recovery. The manipulation leads to hard-coded credentials.
This vulnerability is uniquely identified as CVE-2025-2538. It is possible to initiate the attack remotely. There is no exploit available.