Path Traversal Vulnerability in ESRI ArcGIS Server Affecting Multiple Versions
CVE-2024-51966

4.9MEDIUM

Key Information:

Vendor

Esri

Vendor
CVE Published:
3 March 2025

What is CVE-2024-51966?

A path traversal vulnerability in ESRI ArcGIS Server allows remote authenticated attackers with administrative privileges to traverse the file system. This exploit enables unauthorized access to files outside the intended directory, potentially compromising sensitive information. While the integrity and availability of the system remain unaffected, there is a significant risk to confidentiality, as attackers may access confidential data.

Affected Version(s)

ArcGIS Server Windows all <= 11.3

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-51966 : Path Traversal Vulnerability in ESRI ArcGIS Server Affecting Multiple Versions