CVE-2020-35712: SSRF
Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-35712?
CVE-2020-35712 refers to a vulnerability in Esri ArcGIS Server before version 10.8 that allows Server-Side Request Forgery (SSRF) in some configurations.
How severe is the CVE-2020-35712 vulnerability?
The severity of CVE-2020-35712 is rated as critical with a severity score of 9.8 out of 10.
Which software versions are affected by CVE-2020-35712?
Esri ArcGIS Server versions up to and excluding 10.8 are affected by CVE-2020-35712.
How can I fix the CVE-2020-35712 vulnerability?
To fix the CVE-2020-35712 vulnerability, it is recommended to upgrade to at least version 10.8 of Esri ArcGIS Server.
Where can I find more information about CVE-2020-35712?
You can find more information about CVE-2020-35712 on the Esri support website at the following links: [link1](https://support.esri.com/en/bugs/nimbus/QlVHLTAwMDEyODA2MA==) and [link2](https://support.esri.com/en/technical-article/000022931).