First published: Mon Mar 03 2025(Updated: )
A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify Column properties allowing for the execution of a SQL Injection by a remote authenticated user with elevated (non admin) privileges. There is a high impact to integrity and confidentiality and no impact to availability.
Credit: psirt@esri.com
Affected Software | Affected Version | How to fix |
---|---|---|
ESRI ArcGIS for Server | ||
ESRI ArcGIS for Server | >=10.9.1<=11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-51962 has a high severity rating due to its potential impact on integrity and confidentiality.
To fix CVE-2024-51962, apply the latest security patch provided by Esri for ArcGIS Server.
CVE-2024-51962 affects authenticated users with elevated privileges in ArcGIS Server.
CVE-2024-51962 is a SQL injection vulnerability that allows unauthorized SQL commands to be executed.
Exploitation of CVE-2024-51962 can lead to unauthorized modification of database contents and could compromise data integrity.