Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cxm9-pc6x-88r5

Опубликовано: 03 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.5

Описание

There is an improper access control issue in ArcGIS Server versions 10.9.1 through 11.3 on Windows and Linux, which under unique circumstances, could potentially allow a remote, low privileged authenticated attacker to access secure services published a standalone (Unfederated)

ArcGIS Server instance.  If successful this compromise would have a high impact on Confidentiality, low impact on integrity and no impact to availability of the software.

There is an improper access control issue in ArcGIS Server versions 10.9.1 through 11.3 on Windows and Linux, which under unique circumstances, could potentially allow a remote, low privileged authenticated attacker to access secure services published a standalone (Unfederated)

ArcGIS Server instance.  If successful this compromise would have a high impact on Confidentiality, low impact on integrity and no impact to availability of the software.

EPSS

Процентиль: 27%
0.00096
Низкий

8.5 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 8.5
nvd
11 месяцев назад

There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux, which under unique circumstances, could potentially allow a remote, low privileged authenticated attacker to access secure services published a standalone (Unfederated) ArcGIS Server instance.  If successful this compromise would have a high impact on Confidentiality, low impact on integrity and no impact to availability of the software.

CVSS3: 8.5
fstec
12 месяцев назад

Уязвимость сервера ArcGIS Server, связанная с недостатками разграничения доступа, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 27%
0.00096
Низкий

8.5 High

CVSS3

Дефекты

CWE-284