CVE-2022-38200: BUG-000142376 - Reflected Cross-Site Scripting (XSS) vulnerability in ArcGIS Server.
Published Oct 25, 2022
·Updated
A cross site scripting vulnerability exists in some map service configurations of ArcGIS Server versions 10.8.1 and 10.7.1. Specifically crafted web requests can execute arbitrary JavaScript in the context of the victim's browser.
Affected Software
2 affected components
Esri ArcGIS Server=10.7.1
Esri ArcGIS Server=10.8.1
Remediation
Information
ArcGIS Server Map Service Security 2022 Update 1 Patch
https://support.esri.com/en/download/8042
Event History
Oct 25, 2022
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-38200?
CVE-2022-38200 is a cross-site scripting vulnerability in some map service configurations of ArcGIS Server versions 10.8.1 and 10.7.1.
2
How severe is CVE-2022-38200?
CVE-2022-38200 has a severity rating of 6.1, which is considered medium.
3
Which software versions are affected by CVE-2022-38200?
ArcGIS Server versions 10.8.1 and 10.7.1 are affected by CVE-2022-38200.
4
How can CVE-2022-38200 be exploited?
CVE-2022-38200 can be exploited by sending specifically crafted web requests that execute arbitrary JavaScript in the victim's browser.
5
Is there a fix available for CVE-2022-38200?
Yes, a fix for CVE-2022-38200 is available. Please refer to the official reference for more information.