PT-2025-9558 · Esri · Esri Arcgis Server

Publicado

2025-02-18

·

Atualizado

2025-03-04

·

CVE-2024-51958

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions ESRI ArcGIS Server versions 10.9.1 through 11.3
Description The issue allows a remote authenticated attacker with admin privileges to traverse the file system and access files outside of the intended directory, potentially leading to a high impact on confidentiality. There is no impact to integrity or availability due to the nature of the files that can be accessed.
Recommendations For ESRI ArcGIS Server versions 10.9.1 through 11.3, update to a version that contains a fix for this issue to prevent path traversal exploitation.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-02371
CVE-2024-51958

Produtos afetados

Esri Arcgis Server