Path Traversal Vulnerability in ESRI ArcGIS Server Affecting Multiple Versions
CVE-2024-51966
4.9MEDIUM
What is CVE-2024-51966?
A path traversal vulnerability in ESRI ArcGIS Server allows remote authenticated attackers with administrative privileges to traverse the file system. This exploit enables unauthorized access to files outside the intended directory, potentially compromising sensitive information. While the integrity and availability of the system remain unaffected, there is a significant risk to confidentiality, as attackers may access confidential data.
Affected Version(s)
ArcGIS Server Windows all <= 11.3