We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-25848

BUG-000158039 - There is an information disclosure issue in ArcGIS Server.



AssignerEsri
Reserved2023-02-15
Published2023-08-25
Updated2024-10-08

Description

ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthorized attacker may submit a crafted query that may result in a low severity information disclosure issue. The information disclosed is limited to a single attribute in a database connection string. No business data is disclosed.



MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-319 Cleartext Transmission of Sensitive Information

Product status

Default status
unaffected

10.8.1
affected

10.9.1
affected

11.0
affected

11.1
affected

References

https://www.esri.com/arcgis-blog/products/trust-arcgis/announcements/arcgis-server-map-and-feature-service-security-2023-update-1-patch/

cve.org CVE-2023-25848

nvd.nist.gov CVE-2023-25848

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.