PT-2025-9564 · Esri · Esri Arcgis Server

Published

2025-02-18

·

Updated

2025-03-04

·

CVE-2024-51966

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions ESRI ArcGIS Server versions 10.9.1 through 11.3
Description The issue is related to a path traversal vulnerability. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system and access files outside of the intended directory. This could potentially have a high impact on confidentiality, although there is no impact to integrity or availability due to the nature of the files that can be accessed.
Recommendations For ESRI ArcGIS Server versions 10.9.1 through 11.3, consider restricting access to sensitive files and directories to minimize the risk of exploitation. As a temporary workaround, limit the privileges of authenticated users to reduce the potential impact of the vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-02372
CVE-2024-51966

Affected Products

Esri Arcgis Server