First published: Fri Dec 25 2020(Updated: )
Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Esri ArcGIS Server | <10.8 | |
Linux Linux kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35712 refers to a vulnerability in Esri ArcGIS Server before version 10.8 that allows Server-Side Request Forgery (SSRF) in some configurations.
The severity of CVE-2020-35712 is rated as critical with a severity score of 9.8 out of 10.
Esri ArcGIS Server versions up to and excluding 10.8 are affected by CVE-2020-35712.
To fix the CVE-2020-35712 vulnerability, it is recommended to upgrade to at least version 10.8 of Esri ArcGIS Server.
You can find more information about CVE-2020-35712 on the Esri support website at the following links: [link1](https://support.esri.com/en/bugs/nimbus/QlVHLTAwMDEyODA2MA==) and [link2](https://support.esri.com/en/technical-article/000022931).