SQL Injection Vulnerability in Esri ArcGIS Server on Multiple Platforms
CVE-2025-57870
What is CVE-2025-57870?
A SQL Injection vulnerability has been identified in Esri ArcGIS Server versions 11.3, 11.4, and 11.5, impacting deployments on Windows, Linux, and Kubernetes systems. This security flaw permits remote, unauthenticated attackers to execute arbitrary SQL commands through a specific operation in the ArcGIS Feature Service. Exploiting this vulnerability could lead to unauthorized access, modification, or deletion of sensitive data stored within the Enterprise Geodatabase. It is critical for organizations using these versions to apply security patches promptly to safeguard their data integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ArcGIS Server Windows 11.3 <= 11.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
