Описание
ArcGIS Server version 11.5 and earlier on Windows and Linux does not properly validate uploaded files, which allows remote attackers to upload arbitrary files. However, exploitation is constrained by server-side controls that prevent execution of uploaded content and do not allow modification of existing application files or system configurations. As a result, successful exploitation would have a low impact on confidentiality, integrity, and availability, and would not enable service disruption, privilege escalation, or unauthorized access to sensitive data.
Уязвимые конфигурации
Одновременно
Одно из
EPSS
5.6 Medium
CVSS3
9.8 Critical
CVSS3
Дефекты
Связанные уязвимости
ArcGIS Server version 11.5 and earlier on Windows and Linux does not properly validate uploaded files file, which allows remote attackers to upload arbitrary files.
EPSS
5.6 Medium
CVSS3
9.8 Critical
CVSS3