Show filters
109 Total Results
Displaying 31-40 of 109
Sort by:
Attacker Value
Unknown
CVE-2023-25839
Disclosure Date: July 19, 2023 (last updated October 08, 2023)
There is SQL injection vulnerability in Esri ArcGIS Insights Desktop for Mac and Windows version 2022.1 that may allow a local, authorized attacker to execute arbitrary SQL commands against the back-end database. The effort required to generate the crafted input required to exploit this issue is complex and requires significant effort before a successful attack can be expected.
0
Attacker Value
Unknown
CVE-2023-25838
Disclosure Date: July 19, 2023 (last updated May 22, 2024)
There is SQL injection vulnerability in Esri ArcGIS Insights 2022.1 for ArcGIS Enterprise and that may allow a remote, authorized attacker to execute arbitrary SQL commands against the back-end database. The effort required to generate the crafted input required to exploit this issue is complex and requires significant effort before a successful attack can be expected.
0
Attacker Value
Unknown
CVE-2023-25833
Disclosure Date: May 10, 2023 (last updated October 08, 2023)
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser (no stateful change made or customer data rendered).
0
Attacker Value
Unknown
CVE-2023-25832
Disclosure Date: May 09, 2023 (last updated October 08, 2023)
There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.0 and below that may allow an attacker to trick an authorized user into executing unwanted actions.
0
Attacker Value
Unknown
CVE-2023-25831
Disclosure Date: May 09, 2023 (last updated October 08, 2023)
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1, 10.8.1 and 10.7.1 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
0
Attacker Value
Unknown
CVE-2023-25830
Disclosure Date: May 09, 2023 (last updated October 08, 2023)
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1, 10.8.1 and 10.7.1 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
0
Attacker Value
Unknown
CVE-2023-25829
Disclosure Date: May 09, 2023 (last updated October 08, 2023)
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and 10.9.1 that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.
0
Attacker Value
Unknown
CVE-2023-25834
Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Changes to user permissions in Portal for ArcGIS 10.9.1 and below are incompletely applied in specific use cases. This issue may allow users to access content that they are no longer privileged to access.
0
Attacker Value
Unknown
CVE-2022-38202
Disclosure Date: December 28, 2022 (last updated October 08, 2023)
There is a path traversal vulnerability in Esri ArcGIS Server versions 10.9.1 and below. Successful exploitation may allow a remote, unauthenticated attacker traverse the file system to access files outside of the intended directory on ArcGIS Server. This could lead to the disclosure of sensitive site configuration information (not user datasets).
0
Attacker Value
Unknown
CVE-2022-38212
Disclosure Date: December 05, 2022 (last updated October 08, 2023)
Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.8.1 and below were not fully honored and may allow a remote, unauthenticated attacker to forge requests to arbitrary URLs from the system, potentially leading to network enumeration or reading from hosts inside the network perimeter, a different issue than CVE-2022-38211 and CVE-2022-38203.
0