First published: Tue Sep 24 2013(Updated: )
The mobile-upload feature in Esri ArcGIS for Server 10.1 through 10.2 allows remote authenticated users to upload .exe files by leveraging (1) publisher or (2) administrator privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Esri ArcGIS | =10.1 | |
Esri ArcGIS | =10.2 | |
ESRI ArcGIS for Server | =10.1 | |
ESRI ArcGIS for Server | =10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5221 is considered a medium severity vulnerability due to the ability for authenticated users with certain privileges to upload malicious files.
To mitigate CVE-2013-5221, ensure all software, including Esri ArcGIS for Server versions 10.1 and 10.2, is updated to the latest patched versions provided by Esri.
CVE-2013-5221 affects remote authenticated users of Esri ArcGIS and Esri ArcGIS Server versions 10.1 and 10.2 with publisher or administrator privileges.
CVE-2013-5221 allows the upload of executable (.exe) files through the mobile-upload feature.
The consequences of CVE-2013-5221 include unauthorized execution of potentially malicious code on the server, leading to system compromise.