CVE-2024-51961

There is a local file inclusion vulnerability in ArcGIS Server 11.3 and below that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sensitive configuration information by reading internal files from the remote server.  Due to the nature of the files accessible in this vulnerability the impact to confidentiality is High there is no impact to both integrity or availability.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:esri:arcgis_server:*:*:*:*:*:*:*:*

History

10 Apr 2025, 20:15

Type Values Removed Values Added
Summary There is a local file inclusion vulnerability in ArcGIS Server 10.9.1 thru 11.3 that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sensitive configuration information by reading internal files from the remote server.  Due to the nature of the files accessible in this vulnerability the impact to confidentiality is High there is no impact to both integrity or availability. There is a local file inclusion vulnerability in ArcGIS Server 11.3 and below that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sensitive configuration information by reading internal files from the remote server.  Due to the nature of the files accessible in this vulnerability the impact to confidentiality is High there is no impact to both integrity or availability.
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : unknown
CWE CWE-610
CWE-73

06 Mar 2025, 14:23

Type Values Removed Values Added
First Time Esri arcgis Server
Esri
CWE CWE-610
CPE cpe:2.3:a:esri:arcgis_server:*:*:*:*:*:*:*:*
References () https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch/ - () https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch/ - Vendor Advisory

03 Mar 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-03 20:15

Updated : 2025-04-10 20:15


NVD link : CVE-2024-51961

Mitre link : CVE-2024-51961


JSON object : View

Products Affected

esri

  • arcgis_server
CWE

No CWE.