Known Vulnerabilities for Arcgis Server by Esri
Listed below are 10 of the newest known vulnerabilities associated with "Arcgis Server" by "Esri".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-25848 json | ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthoriz... | 5.3 - MEDIUM | 2023-08-25 | 2023-08-31 |
| CVE-2022-38202 json | There is a path traversal vulnerability in Esri ArcGIS Server versions 10.9.1 and below. Successful exploitation may allow a ... | 7.5 - HIGH | 2022-12-28 | 2023-01-06 |
| CVE-2022-38200 json | A cross site scripting vulnerability exists in some map service configurations of ArcGIS Server versions 10.8.1 and 10.7.1. S... | 6.1 - MEDIUM | 2022-10-25 | 2022-10-31 |
| CVE-2022-38199 json | A remote file download issue can occur in some capabilities of Esri ArcGIS Server web services that may in some edge cases al... | 6.1 - MEDIUM | 2022-10-25 | 2022-10-28 |
| CVE-2022-38198 json | There is a reflected cross site scripting issue in the Esri ArcGIS Server services directory versions 10.9.1 and below that m... | 6.1 - MEDIUM | 2022-10-25 | 2022-10-26 |
| CVE-2022-38197 json | Esri ArcGIS Server versions 10.9.1 and below have an unvalidated redirect issue that may allow a remote, unauthenticated atta... | 6.1 - MEDIUM | 2022-10-25 | 2022-10-31 |
| CVE-2022-38196 json | Esri ArcGIS Server versions 10.9.1 and prior have a path traversal vulnerability that may result in a denial of service by al... | 8.1 - HIGH | 2022-10-25 | 2022-10-31 |
| CVE-2022-38195 json | There is as reflected cross site scripting issue in Esri ArcGIS Server versions 10.9.1 and below which may allow a remote una... | 6.1 - MEDIUM | 2022-10-25 | 2022-10-27 |
| CVE-2021-29116 json | A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server feature services versions 10.8.1 and 10.9 (only) feat... | 6.1 - MEDIUM | 2021-12-07 | 2023-11-07 |
| CVE-2021-29114 json | A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthentica... | 9.8 - CRITICAL | 2021-12-07 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Esri | Arcgis Server | 10.8.1 | |||
| Application | Esri | Arcgis Server | 10.8 | |||
| Application | Esri | Arcgis Server | 10.7.1 | |||
| Application | Esri | Arcgis Server | 10.7 | |||
| Application | Esri | Arcgis Server | 10.6 | |||
| Application | Esri | Arcgis Server | 10.5 | |||
| Application | Esri | Arcgis Server | 10.4.1 | |||
| Application | Esri | Arcgis Server | 10.4 | |||
| Application | Esri | Arcgis Server | 10.3 | |||
| Application | Esri | Arcgis Server | 10.2.2 |