CVE-2024-51958
CVSS 3.1 Score 4.9 of 10 (medium)
Details
Summary
CVE-2024-51958 is a path traversal vulnerability affecting ESRI ArcGIS Server versions 10.9.1 to 11.3. This issue allows a remote, authenticated attacker with admin privileges to bypass intended directory restrictions and access files outside the intended location. While there is no reported impact on system integrity or availability, the potential confidentiality breach poses a significant risk. Successful exploitation could result in the exposure of sensitive information. It is strongly recommended that users update their ESRI ArcGIS Server software to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Esri