CVE-2024-51966: Directory traversal vulnerability in ArcGIS Server
There is a path traversal vulnerability in ESRI ArcGIS Server versions 10.9.1 thru 11.3. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory. There is no impact to integrity or availability due to the nature of the files that can be accessed, but there is a potential high impact to confidentiality.
Other sources
There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory. There is no impact to integrity or availability due to the nature of the files that can be accessed, but there is a potential high impact to confidentiality.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-51966?
CVE-2024-51966 is classified as a high severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2024-51966?
To fix CVE-2024-51966, update ESRI ArcGIS Server to versions later than 11.3 or apply the recommended security patches.
Who is impacted by CVE-2024-51966?
CVE-2024-51966 affects users of ESRI ArcGIS Server versions 10.9.1 through 11.3 with authenticated admin access.
What type of attack can CVE-2024-51966 enable?
CVE-2024-51966 can enable remote authenticated attackers to perform path traversal attacks, accessing sensitive files outside the intended directory.
Is there a workaround for CVE-2024-51966?
Currently, there are no documented workarounds for CVE-2024-51966, and the best course of action is to apply updates.