CVE-2023-25848: BUG-000158039 - There is an information disclosure issue in ArcGIS Server.
Published Aug 25, 2023
·Updated
ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthorized attacker may submit a crafted query that may result in a low severity information disclosure issue.
The information disclosed is limited to a single attribute in a database connection string. No business data is disclosed.
Affected Software
1 affected component
Esri ArcGIS Server>=10.8.1<=11.0
Event History
Aug 25, 2023
CVE Published
via MITRE·06:44 PM
Data Sourced
via MITRE·06:44 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-25848.
2
What is the severity of CVE-2023-25848?
The severity of CVE-2023-25848 is medium with a CVSS score of 5.3.
3
What is the affected software?
The affected software is ArcGIS Enterprise Server versions 11.0 and below.
4
What is the impact of CVE-2023-25848?
CVE-2023-25848 may result in a low severity information disclosure issue.
5
How do I fix CVE-2023-25848?
To fix CVE-2023-25848, users are advised to apply the ArcGIS Server Map and Feature Service Security 2023 Update 1 patch.