CVE-2012-4949: SQL Injection
Published Nov 14, 2012
·Updated
SQL injection vulnerability in ESRI ArcGIS 10.1 allows remote authenticated users to execute arbitrary SQL commands via the where parameter to a query URI for a REST service.
Affected Software
2 affected components
Esri ArcGIS=10.1
Esri ArcGIS Server=10.1
Event History
Nov 14, 2012
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4949?
CVE-2012-4949 has a medium severity rating due to its potential for unauthorized data manipulation.
2
How do I fix CVE-2012-4949?
To fix CVE-2012-4949, update to a later version of ESRI ArcGIS or apply any available security patches.
3
What are the implications of CVE-2012-4949?
CVE-2012-4949 enables remote authenticated users to craft SQL queries that could lead to unauthorized data access.
4
Who is affected by CVE-2012-4949?
CVE-2012-4949 affects users of ESRI ArcGIS 10.1 and ESRI ArcGIS Server 10.1.
5
Can CVE-2012-4949 be exploited over the internet?
Yes, CVE-2012-4949 can be exploited if an attacker has authenticated access to the REST service.