CVE-2022-38196: BUG-000150537 - ArcGIS Server has a local file inclusion (LFI) vulnerability
Esri ArcGIS Server versions 10.9.1 and prior have a path traversal vulnerability that may result in a denial of service by allowing a remote, authenticated attacker to overwrite internal ArcGIS Server directory.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-38196?
CVE-2022-38196 is a path traversal vulnerability in Esri ArcGIS Server versions 10.9.1 and prior that allows a remote, authenticated attacker to overwrite internal ArcGIS Server directory.
How severe is CVE-2022-38196?
CVE-2022-38196 has a severity rating of 8.1 (high).
How does CVE-2022-38196 affect Esri ArcGIS Server?
CVE-2022-38196 affects Esri ArcGIS Server versions 10.9.1 and prior, allowing a remote, authenticated attacker to overwrite internal ArcGIS Server directory, potentially resulting in a denial of service.
Which versions of Esri ArcGIS Server are affected?
Esri ArcGIS Server versions 10.9.1 and prior are affected by CVE-2022-38196.
Is there a patch available for CVE-2022-38196?
Yes, a patch for CVE-2022-38196 is available. Please refer to the Esri ArcGIS Blog for further information.