CVE-2024-51958: Directory traversal vulnerability in the admin api for service thumbnails
There is a path traversal vulnerability in ESRI ArcGIS Server versions 10.9.1 thru 11.3. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory. There is no impact to integrity or availability due to the nature of the files that can be accessed, but there is a potential high impact to confidentiality.
Other sources
There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory. There is no impact to integrity or availability due to the nature of the files that can be accessed, but there is a potential high impact to confidentiality.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-51958?
CVE-2024-51958 is classified as a high severity vulnerability due to its potential for remote file system access.
How do I fix CVE-2024-51958?
To fix CVE-2024-51958, upgrade ESRI ArcGIS Server to version 11.4 or later, which includes patches for this vulnerability.
What versions of ArcGIS Server are affected by CVE-2024-51958?
CVE-2024-51958 affects ESRI ArcGIS Server versions 10.9.1 through 11.3.
Can CVE-2024-51958 be exploited remotely?
Yes, CVE-2024-51958 can be exploited by a remote authenticated attacker with admin privileges.
What impact does CVE-2024-51958 have on system security?
CVE-2024-51958 allows attackers to traverse the file system and access restricted files, potentially compromising system security.