PT-2022-24279 · Esri · Arcgis Server

Published

2022-12-28

·

Updated

2024-08-31

·

CVE-2022-38202

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Esri ArcGIS Server versions 10.9.1 and below
Description The issue allows a remote, unauthenticated attacker to traverse the file system and access files outside of the intended directory on ArcGIS Server. This could lead to the disclosure of sensitive site configuration information, but not user datasets.
Recommendations For Esri ArcGIS Server versions 10.9.1 and below, update to a version above 10.9.1 to resolve the issue. At the moment, there is no information about other specific fixes for this vulnerability.

Fix

Path traversal

Relative Path Traversal

Weakness Enumeration

Related Identifiers

CVE-2022-38202

Affected Products

Arcgis Server