Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2cj7-q7vw-gwx8

Опубликовано: 03 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

There is a path traversal vulnerability in ESRI ArcGIS Server versions 10.9.1 thru 11.3. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory. There is no impact to integrity or availability due to the nature of the files that can be accessed, but there is a potential high impact to confidentiality.

There is a path traversal vulnerability in ESRI ArcGIS Server versions 10.9.1 thru 11.3. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory. There is no impact to integrity or availability due to the nature of the files that can be accessed, but there is a potential high impact to confidentiality.

EPSS

Процентиль: 20%
0.00063
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 4.9
nvd
6 месяцев назад

There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory. There is no impact to integrity or availability due to the nature of the files that can be accessed, but there is a potential high impact to confidentiality.

CVSS3: 4.9
fstec
6 месяцев назад

Уязвимость сервера ArcGIS Server, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 20%
0.00063
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-22