Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-5515 | There is a path traversal vulnerability in ESRI ArcGIS Server versions 10.9.1 thru 11.3. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory. There is no impact to integrity or availability due to the nature of the files that can be accessed, but there is a potential high impact to confidentiality. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 10 Apr 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | There is a path traversal vulnerability in ESRI ArcGIS Server versions 10.9.1 thru 11.3. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory. There is no impact to integrity or availability due to the nature of the files that can be accessed, but there is a potential high impact to confidentiality. | There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory. There is no impact to integrity or availability due to the nature of the files that can be accessed, but there is a potential high impact to confidentiality. |
Thu, 06 Mar 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Esri
Esri arcgis Server |
|
| CPEs | cpe:2.3:a:esri:arcgis_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Esri
Esri arcgis Server |
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | There is a path traversal vulnerability in ESRI ArcGIS Server versions 10.9.1 thru 11.3. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory. There is no impact to integrity or availability due to the nature of the files that can be accessed, but there is a potential high impact to confidentiality. | |
| Title | Directory traversal vulnerability in ArcGIS Server | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Esri
Published:
Updated: 2025-04-10T19:29:07.421Z
Reserved: 2024-11-04T16:54:40.931Z
Link: CVE-2024-51966
Updated: 2025-03-03T20:33:43.228Z
Status : Modified
Published: 2025-03-03T20:15:43.387
Modified: 2025-04-10T20:15:21.850
Link: CVE-2024-51966
No data.
OpenCVE Enrichment
No data.
EUVD