CVE-2025-57870: BUG-000179884 - There is a security vulnerability in ArcGIS Server Feature Services.
A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands via a specific ArcGIS Feature Service operation. Successful exploitation can potentially result in unauthorized access, modification, or deletion of data from the underlying Enterprise Geodatabase.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57870?
CVE-2025-57870 is a high-severity SQL Injection vulnerability that allows remote, unauthenticated attackers to execute arbitrary SQL commands.
How do I fix CVE-2025-57870?
To fix CVE-2025-57870, you should apply the latest security patch provided by Esri for ArcGIS Server versions 11.3, 11.4, and 11.5.
Which versions of Esri ArcGIS Server are affected by CVE-2025-57870?
CVE-2025-57870 affects Esri ArcGIS Server versions 11.3, 11.4, and 11.5.
What types of attacks can be executed due to CVE-2025-57870?
CVE-2025-57870 allows attackers to execute arbitrary SQL commands, potentially leading to data leakage or modification.
Is user authentication required to exploit CVE-2025-57870?
No, CVE-2025-57870 can be exploited by unauthenticated attackers, which increases its risk.