CVE-2024-51962: SQL injection vulnerability in ArcGIS Server
A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify column properties in a manner that could lead to SQL injection when performed by a remote authenticated user requiring elevated, non‑administrative privileges. Exploitation is restricted to users with advanced application‑specific permissions, indicating high privileges are required. Successful exploitation would have a high impact on integrity and confidentiality, with no impact on availability.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-51962?
CVE-2024-51962 has a high severity rating due to its potential impact on integrity and confidentiality.
How do I fix CVE-2024-51962?
To fix CVE-2024-51962, apply the latest security patch provided by Esri for ArcGIS Server.
Who is affected by CVE-2024-51962?
CVE-2024-51962 affects authenticated users with elevated privileges in ArcGIS Server.
What type of vulnerability is CVE-2024-51962?
CVE-2024-51962 is a SQL injection vulnerability that allows unauthorized SQL commands to be executed.
What are the consequences of exploiting CVE-2024-51962?
Exploitation of CVE-2024-51962 can lead to unauthorized modification of database contents and could compromise data integrity.