PT-2013-5454 · Esri · Esri Arcgis For Server

·

CVE-2013-5221

·

Publicado

2013-09-24

·

Atualizado

2024-07-11

CVSS v2.0

3.5

Baixa

VetorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Esri ArcGIS for Server versions 10.1 through 10.2
Description The mobile-upload feature in Esri ArcGIS for Server allows remote authenticated users to upload .exe files by leveraging publisher or administrator privileges.
Recommendations For versions 10.1 through 10.2, consider restricting the mobile-upload feature to prevent unauthorized file uploads until a fix is available. As a temporary workaround, consider disabling the mobile-upload feature for users with publisher or administrator privileges to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2013-5221

Produtos afetados

Esri Arcgis For Server