CVE-2023-25839: BUG-000157278 – ArcGIS Insights has a security vulnerability - desktop
There is SQL injection vulnerability in Esri ArcGIS Insights Desktop for Mac and Windows version 2022.1 that may allow a local, authorized attacker to execute arbitrary SQL commands against the back-end database. The effort required to generate the crafted input required to exploit this issue is complex and requires significant effort before a successful attack can be expected.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-25839?
CVE-2023-25839 is a SQL injection vulnerability in Esri ArcGIS Insights Desktop for Mac and Windows version 2022.1 that may allow a local, authorized attacker to execute arbitrary SQL commands against the back-end database.
How severe is CVE-2023-25839?
CVE-2023-25839 has a severity level of high (7).
Which software versions are affected by CVE-2023-25839?
Esri ArcGIS Insights Desktop for Mac and Windows version 2022.1 is affected by CVE-2023-25839.
How can an attacker exploit CVE-2023-25839?
An attacker can exploit CVE-2023-25839 by generating crafted input to execute arbitrary SQL commands against the back-end database.
Where can I find more information about CVE-2023-25839?
More information about CVE-2023-25839 can be found at the following link: [Esri ArcGIS Insights Security Patches](https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-insights-security-patches-for-arcgis-insights-2022-1-are-now-available/)