CVE-2022-38199
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/10/2022
Last modified:
28/10/2022
Description
A remote file download issue can occur in some capabilities of Esri ArcGIS Server web services that may in some edge cases allow a remote, unauthenticated attacker to induce an unsuspecting victim to launch a process in the victim's PATH environment. Current browsers provide users with warnings against running unsigned executables downloaded from the internet.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:esri:arcgis_server:10.7.1:*:*:*:*:*:x64:* | ||
| cpe:2.3:a:esri:arcgis_server:10.8.1:*:*:*:*:*:x64:* | ||
| cpe:2.3:a:esri:arcgis_server:10.9.1:*:*:*:*:*:x64:* |
To consult the complete list of CPE names with products and versions, see this page



