Логотип exploitDog
bind:CVE-2024-51954
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-51954

Количество 3

Количество 3

nvd логотип

CVE-2024-51954

11 месяцев назад

There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under unique circumstances, could allow a remote, low‑privileged authenticated attacker to access secure services published to a standalone (unfederated) ArcGIS Server instance. Successful exploitation results in unauthorized access to protected services outside the attacker’s originally assigned authorization boundary, constituting a scope change. If exploited, this issue would have a high impact on confidentiality, a low impact on integrity, and no impact on the availability of the software.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-cxm9-pc6x-88r5

11 месяцев назад

There is an improper access control issue in ArcGIS Server versions 10.9.1 through 11.3 on Windows and Linux, which under unique circumstances, could potentially allow a remote, low privileged authenticated attacker to access secure services published a standalone (Unfederated) ArcGIS Server instance.  If successful this compromise would have a high impact on Confidentiality, low impact on integrity and no impact to availability of the software.

CVSS3: 8.5
EPSS: Низкий
fstec логотип

BDU:2025-02368

12 месяцев назад

Уязвимость сервера ArcGIS Server, связанная с недостатками разграничения доступа, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 8.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-51954

There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under unique circumstances, could allow a remote, low‑privileged authenticated attacker to access secure services published to a standalone (unfederated) ArcGIS Server instance. Successful exploitation results in unauthorized access to protected services outside the attacker’s originally assigned authorization boundary, constituting a scope change. If exploited, this issue would have a high impact on confidentiality, a low impact on integrity, and no impact on the availability of the software.

CVSS3: 8.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-cxm9-pc6x-88r5

There is an improper access control issue in ArcGIS Server versions 10.9.1 through 11.3 on Windows and Linux, which under unique circumstances, could potentially allow a remote, low privileged authenticated attacker to access secure services published a standalone (Unfederated) ArcGIS Server instance.  If successful this compromise would have a high impact on Confidentiality, low impact on integrity and no impact to availability of the software.

CVSS3: 8.5
0%
Низкий
11 месяцев назад
fstec логотип
BDU:2025-02368

Уязвимость сервера ArcGIS Server, связанная с недостатками разграничения доступа, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 8.5
0%
Низкий
12 месяцев назад

Уязвимостей на страницу