CWE
312
Advisory Published
Updated

CVE-2022-2569: ARC Informatique PcVue

First published: Wed Aug 24 2022(Updated: )

The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session data stored in the OAuth database belonging to legitimate users

Credit: ics-cert@hq.dhs.gov

Affected SoftwareAffected VersionHow to fix
Esri ArcInfo<12.0.27
Esri ArcInfo>=15<=15.2.2

Remedy

PcVue 12: The fix is available in Maintenance release 12.0.27 After installing the fix, users should update the Web Deployment Console (WDC) and re-deploy the Web Server. All users using the affected component should install a patched release of the WDC and re-deploy the Web Server. This will allow the WDC to update and protect the database connection string, including clearing any sensitive information stored in the web.config file.

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2022-2569?

    CVE-2022-2569 has been identified with a high severity rating due to the exposure of sensitive session data in cleartext.

  • How do I fix CVE-2022-2569?

    To fix CVE-2022-2569, ensure that sensitive information is stored in a secure manner, such as encrypting session data.

  • Who is affected by CVE-2022-2569?

    CVE-2022-2569 affects devices running Esri ArcInfo versions up to 12.0.27 and between versions 15.0.0 and 15.2.2.

  • What type of data is compromised in CVE-2022-2569?

    CVE-2022-2569 compromises sensitive session data that is stored in the OAuth database in cleartext.

  • Can an authenticated user exploit CVE-2022-2569?

    Yes, an authenticated user may exploit CVE-2022-2569 to access session data belonging to legitimate users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203