CVE-2024-51961

HIGH

ArcGIS Server <11.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

There is a local file inclusion vulnerability in ArcGIS Server 11.3 and below that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sensitive configuration information by reading internal files from the remote server.  Due to the nature of the files accessible in this vulnerability the impact to confidentiality is High there is no impact to both integrity or availability.

Scores

CVSS v3 7.5
EPSS 0.0020
EPSS Percentile 42.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-610 CWE-73
Status published
Products (1)
esri/arcgis_server 10.9.1 - 11.3
Published Mar 03, 2025
Tracked Since Feb 18, 2026