A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify Column properties allowing for the execution of a SQL Injection by a remote authenticated user with elevated (non admin) privileges.  There is a high impact to integrity and confidentiality and no impact to availability.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-5530 A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify Column properties allowing for the execution of a SQL Injection by a remote authenticated user with elevated (non admin) privileges.  There is a high impact to integrity and confidentiality and no impact to availability.
Fixes

Solution

Install ArcGIS Server security 2025 update 1.


Workaround

No workaround given by the vendor.

History

Thu, 06 Mar 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Esri
Esri arcgis Server
CPEs cpe:2.3:a:esri:arcgis_server:*:*:*:*:*:*:*:*
Vendors & Products Esri
Esri arcgis Server

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 20:15:00 +0000

Type Values Removed Values Added
Description A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify Column properties allowing for the execution of a SQL Injection by a remote authenticated user with elevated (non admin) privileges.  There is a high impact to integrity and confidentiality and no impact to availability.
Title SQL injection vulnerability in ArcGIS Server
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published:

Updated: 2025-04-10T19:20:17.430Z

Reserved: 2024-11-04T16:54:40.930Z

Link: CVE-2024-51962

cve-icon Vulnrichment

Updated: 2025-03-03T20:35:28.404Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-03T20:15:43.043

Modified: 2025-03-06T14:23:26.167

Link: CVE-2024-51962

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.