Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14677 | Violation of Secure Design Principles, Hidden Functionality, Incorrect Provision of Specified Functionality vulnerability in ArcGIS (Authentication) allows Privilege Abuse, Manipulating Hidden Fields, Configuration/Environment Manipulation. The ArcGIS client_credentials OAuth 2.0 API implementation does not adhere to the RFC/standards; This hidden (known and by-design, but undocumented) functionality enables a requestor (referred to as client in RFC 6749) to request an, undocumented, custom token expiration from ArcGIS (referred to as authorization server in RFC 6749). |
No reference.
Mon, 19 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | “This CVE ID is Rejected and will not be used. As the CNA of record ESRI has rejected this CVE and Reserved CVE-2025-4856 to address this issue.” | “This CVE ID is Rejected and will not be used. As the CNA of record ESRI has rejected this CVE as it is not a vulnerability” |
Fri, 16 May 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-657 CWE-684 CWE-912 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Fri, 16 May 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | ArcGIS Hidden Functionality Allows Insecure OAuth 2.0 Based Authentication | |
| Metrics |
ssvc
|
Fri, 16 May 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Violation of Secure Design Principles, Hidden Functionality, Incorrect Provision of Specified Functionality vulnerability in ArcGIS (Authentication) allows Privilege Abuse, Manipulating Hidden Fields, Configuration/Environment Manipulation. The ArcGIS client_credentials OAuth 2.0 API implementation does not adhere to the RFC/standards; This hidden (known and by-design, but undocumented) functionality enables a requestor (referred to as client in RFC 6749) to request an, undocumented, custom token expiration from ArcGIS (referred to as authorization server in RFC 6749). | “This CVE ID is Rejected and will not be used. As the CNA of record ESRI has rejected this CVE and Reserved CVE-2025-4856 to address this issue.” |
| Metrics |
cvssV4_0
|
cvssV4_0
|
Thu, 15 May 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV4_0
|
cvssV4_0
|
Wed, 14 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 14 May 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Violation of Secure Design Principles, Hidden Functionality, Incorrect Provision of Specified Functionality vulnerability in ArcGIS (Authentication) allows Privilege Abuse, Manipulating Hidden Fields, Configuration/Environment Manipulation. The ArcGIS client_credentials OAuth 2.0 API implementation does not adhere to the RFC/standards; This hidden (known and by-design, but undocumented) functionality enables a requestor (Referred to as client in RFC 6749) to request an, undocumented, custom token expiration from ArcGIS (Referred to as authorization server in RFC 6749). | Violation of Secure Design Principles, Hidden Functionality, Incorrect Provision of Specified Functionality vulnerability in ArcGIS (Authentication) allows Privilege Abuse, Manipulating Hidden Fields, Configuration/Environment Manipulation. The ArcGIS client_credentials OAuth 2.0 API implementation does not adhere to the RFC/standards; This hidden (known and by-design, but undocumented) functionality enables a requestor (referred to as client in RFC 6749) to request an, undocumented, custom token expiration from ArcGIS (referred to as authorization server in RFC 6749). |
Wed, 14 May 2025 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Violation of Secure Design Principles, Hidden Functionality, Incorrect Provision of Specified Functionality vulnerability in ArcGIS (Authentication) allows Privilege Abuse, Manipulating Hidden Fields, Configuration/Environment Manipulation. The ArcGIS client_credentials OAuth 2.0 API implementation does not adhere to the RFC/standards; This hidden (known and by-design, but undocumented) functionality enables a requestor (Referred to as client in RFC 6749) to request an, undocumented, custom token expiration from ArcGIS (Referred to as authorization server in RFC 6749). | |
| Title | ArcGIS Hidden Functionality Allows Insecure OAuth 2.0 Based Authentication | |
| Weaknesses | CWE-657 CWE-684 CWE-912 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: REJECTED
Assigner: VULSec
Published:
Updated: 2025-05-19T19:07:02.724Z
Reserved: 2024-11-06T08:36:01.058Z
Link: CVE-2025-0020
Updated:
Status : Rejected
Published: 2025-05-14T08:15:33.863
Modified: 2025-05-19T19:15:47.690
Link: CVE-2025-0020
No data.
OpenCVE Enrichment
No data.
No weakness.
EUVD