Impact
ArcGIS Server contains a directory traversal flaw that allows an unauthenticated attacker to craft path parameters and write arbitrary files on the host. The CWE‑22 weakness can enable the attacker to modify configuration files or upload hostile code, resulting in full administrative control over the ArcGIS Server and significant compromise of confidentiality, integrity, and availability.
Affected Systems
The flaw affects Esri ArcGIS Server running on Windows and Linux, including all releases up to version 12.0 and prior. ArcGIS Enterprise deployments on Kubernetes are not impacted.
Risk and Exploitability
The CVSS score of 9.8 marks this vulnerability as critical, while the EPSS score of less than 1 % indicates that widespread exploitation has not yet been observed. The vulnerability can be triggered from any host that can reach the ArcGIS Server because no authentication is required. Although it is not listed in the CISA KEV catalog, the high severity and broad version impact warrant immediate attention.
OpenCVE Enrichment