CVE-2022-38202: BUG-000152121 - Directory traversal vulnerability in ArcGIS Server.
There is a path traversal vulnerability in Esri ArcGIS Server versions 10.9.1 and below. Successful exploitation may allow a remote, unauthenticated attacker traverse the file system to access files outside of the intended directory on ArcGIS Server. This could lead to the disclosure of sensitive site configuration information (not user datasets).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this path traversal vulnerability?
The vulnerability ID for this path traversal vulnerability is CVE-2022-38202.
Which versions of Esri ArcGIS Server are affected by this vulnerability?
Esri ArcGIS Server versions 10.9.1 and below are affected by this vulnerability.
What is the severity of CVE-2022-38202?
The severity of CVE-2022-38202 is high, with a CVSS score of 7.5.
What can a remote, unauthenticated attacker do if they exploit this vulnerability?
A remote, unauthenticated attacker can traverse the file system to access files outside of the intended directory on ArcGIS Server, potentially leading to the disclosure of sensitive information.
How can I fix CVE-2022-38202?
To fix CVE-2022-38202, it is recommended to update Esri ArcGIS Server to a version above 10.9.1 or apply the security patch provided by Esri.