BUG-000157278 – ArcGIS Insights has a security vulnerability.
CVE-2023-25838

7.5HIGH

Key Information:

Vendor

Esri

Vendor
CVE Published:
19 July 2023

What is CVE-2023-25838?

A SQL injection vulnerability has been identified in Esri ArcGIS Insights 2022.1 for ArcGIS Enterprise. This vulnerability could allow an authorized remote attacker to execute arbitrary SQL commands on the backend database. The exploitation of this vulnerability requires substantial effort, necessitating complex crafted input to successfully manipulate the database. Organizations using affected versions are urged to apply security patches promptly to mitigate potential risks.

Affected Version(s)

ArcGIS Insights x64 2022.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-25838 : BUG-000157278 – ArcGIS Insights has a security vulnerability.