First published: Wed Jul 08 2015(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for Desktop, ArcGIS for Engine, and ArcGIS for Server 10.2.2 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Esri ArcGIS Desktop | <=10.2.2 | |
Esri ArcGIS Engine | <=10.2.2 | |
ESRI ArcGIS for Server | <=10.2.2 | |
Esri ArcGIS Server | <=10.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9741 has a high severity rating due to the potential for remote attackers to exploit cross-site scripting vulnerabilities.
CVE-2014-9741 affects ESRI ArcGIS for Desktop, ArcGIS for Engine, and ArcGIS for Server versions up to and including 10.2.2.
To fix CVE-2014-9741, update your affected ESRI ArcGIS software to the latest version that addresses these vulnerabilities.
CVE-2014-9741 facilitates cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary web scripts or HTML.
Organizations using ESRI ArcGIS software versions up to 10.2.2 are vulnerable to CVE-2014-9741 and should take immediate action.