CVE-2024-51962
8.7
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Exploitability: 2.3 / Impact: 5.8
Source: NVD
Description
A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify column properties in a manner that could lead to SQL injection when performed by a remote authenticated user requiring elevated, non‑administrative privileges. Exploitation is restricted to users with advanced application‑specific permissions, indicating high privileges are required. Successful exploitation would have a high impact on integrity and confidentiality, with no impact on availability.
Affected (1)
Products: Esri: Arcgis Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 10.9.1 to 11.3 |
References (1)
Source: psirt@esri.com
Vendor Advisory
Timeline
No history available yet.