PT-2025-43271 · Esri · Arcgis Server

Published

2025-10-22

·

Updated

2025-11-29

·

CVE-2025-57870

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Esri ArcGIS Server versions 11.3 through 11.5
Description A SQL Injection issue exists in Esri ArcGIS Server. This allows a remote, unauthenticated attacker to execute arbitrary SQL commands through a specific ArcGIS Feature Service operation. Exploitation could lead to unauthorized access, modification, or deletion of data from the underlying Enterprise Geodatabase. The issue is related to a lack of protection measures for the structure of SQL requests.
Recommendations Update Esri ArcGIS Server to a version later than 11.5.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-13412
CVE-2025-57870

Affected Products

Arcgis Server