Description
A remote file download issue can occur in some capabilities of Esri ArcGIS Server web services that may in some edge cases allow a remote, unauthenticated attacker to induce an unsuspecting victim to launch a process in the victim's PATH environment. Current browsers provide users with warnings against running unsigned executables downloaded from the internet.
No analysis available yet.
Remediation
Vendor Workaround
Secure ArcGIS Server web services Install ArcGIS Server 2022 Security update 1
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-40792 | A remote file download issue can occur in some capabilities of Esri ArcGIS Server web services that may in some edge cases allow a remote, unauthenticated attacker to induce an unsuspecting victim to launch a process in the victim's PATH environment. Current browsers provide users with warnings against running unsigned executables downloaded from the internet. |
References
History
Thu, 10 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Esri
Published:
Updated: 2025-04-10T14:56:20.074Z
Reserved: 2022-08-12T00:00:00.000Z
Link: CVE-2022-38199
Updated: 2024-08-03T10:45:53.098Z
Status : Modified
Published: 2022-10-25T17:15:55.473
Modified: 2024-11-21T07:16:02.720
Link: CVE-2022-38199
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD