CVE-2024-51966

MEDIUM

ESRI ArcGIS Server <11.3 - Path Traversal

Title source: llm
STIX 2.1

Description

There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory. There is no impact to integrity or availability due to the nature of the files that can be accessed, but there is a potential high impact to confidentiality.

Scores

CVSS v3 4.9
EPSS 0.0011
EPSS Percentile 29.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
esri/arcgis_server 10.9.1 - 11.3
Published Mar 03, 2025
Tracked Since Feb 18, 2026