First published: Mon May 03 2021(Updated: )
ArcGIS GeoEvent Server versions 10.8.1 and below has a read-only directory path traversal vulnerability that could allow an unauthenticated, remote attacker to perform directory traversal attacks and read arbitrary files on the system.
Credit: psirt@esri.com psirt@esri.com
Affected Software | Affected Version | How to fix |
---|---|---|
ArcGIS GeoEvent Server | <=10.8.1 | |
Esri Arcgis Geoevent Server | <=10.8.1 |
Esri has released a patch to address this issue.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.