SQL Injection Vulnerability in Esri ArcGIS Server on Multiple Platforms
CVE-2025-57870

10CRITICAL

Key Information:

Vendor

Esri

Vendor
CVE Published:
22 October 2025

What is CVE-2025-57870?

A SQL Injection vulnerability has been identified in Esri ArcGIS Server versions 11.3, 11.4, and 11.5, impacting deployments on Windows, Linux, and Kubernetes systems. This security flaw permits remote, unauthenticated attackers to execute arbitrary SQL commands through a specific operation in the ArcGIS Feature Service. Exploiting this vulnerability could lead to unauthorized access, modification, or deletion of sensitive data stored within the Enterprise Geodatabase. It is critical for organizations using these versions to apply security patches promptly to safeguard their data integrity.

Affected Version(s)

ArcGIS Server Windows 11.3 <= 11.5

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.