CVE-2024-51954

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
03/03/2025
Last modified:
10/04/2025

Description

There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux, which under unique circumstances, could potentially allow a remote, low privileged authenticated attacker to access secure services published a standalone (Unfederated)<br /> <br /> ArcGIS Server instance.  If successful this compromise would have a high impact on Confidentiality, low impact on integrity and no impact to availability of the software.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:esri:arcgis_server:*:*:*:*:*:*:*:* 10.9.1 (including) 11.3 (including)
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*