PT-2025-9558 · Esri · Esri Arcgis Server
Publicado
2025-02-18
·
Atualizado
2025-03-04
·
CVE-2024-51958
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ESRI ArcGIS Server versions 10.9.1 through 11.3
Description
The issue allows a remote authenticated attacker with admin privileges to traverse the file system and access files outside of the intended directory, potentially leading to a high impact on confidentiality. There is no impact to integrity or availability due to the nature of the files that can be accessed.
Recommendations
For ESRI ArcGIS Server versions 10.9.1 through 11.3, update to a version that contains a fix for this issue to prevent path traversal exploitation.
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Esri Arcgis Server