CVE-2019-16193: XSS
Published Sep 11, 2019
·Updated
In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack through the EDIT MY PROFILE feature.
Affected Software
1 affected component
Esri ArcGIS Enterprise=10.6.1
Event History
Sep 11, 2019
CVE Published
via MITRE·11:53 AM
Data Sourced
via MITRE·11:53 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this ArcGIS Enterprise vulnerability?
The vulnerability ID for this ArcGIS Enterprise vulnerability is CVE-2019-16193.
2
What is the severity of CVE-2019-16193?
The severity of CVE-2019-16193 is medium with a CVSS score of 5.4.
3
How can a crafted IFRAME element trigger the Cross Frame Scripting (XFS) attack in ArcGIS Enterprise 10.6.1?
A crafted IFRAME element can be used to trigger the Cross Frame Scripting (XFS) attack through the EDIT MY PROFILE feature in ArcGIS Enterprise 10.6.1.
4
Which version of ArcGIS Enterprise is affected by CVE-2019-16193?
ArcGIS Enterprise version 10.6.1 is affected by CVE-2019-16193.
5
How can I fix CVE-2019-16193 in ArcGIS Enterprise 10.6.1?
To fix CVE-2019-16193 in ArcGIS Enterprise 10.6.1, it is recommended to apply the necessary patches or updates provided by Esri.