SQL injection vulnerability in ArcGIS Server
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.3epss 1.0%
exploitation probability
1.0%top 39% of all CVEs
observed exploitation
nono source reports it
In short
ArcGIS Server versions 10.9 and below have a SQL injection flaw in their feature services that lets attackers send specially crafted requests to steal, modify, or delete database information without needing to log in.
Technical detail
SQL injection vulnerability in ArcGIS Server feature services (v10.9 and below) allows unauthenticated remote attackers to execute arbitrary SQL commands through maliciously crafted queries, compromising confidentiality, integrity, and availability of backend databases.
Summary generated and translated by AI from the official description.
A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthenticated attacker to impact the confidentiality, integrity and availability of targeted services via specifically crafted queries.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected products
Esri · ArcGIS Server