CVE-2023-25848

ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthorized attacker may submit a crafted query that may result in a low severity information disclosure issue. The information disclosed is limited to a single attribute in a database connection string. No business data is disclosed.
Configurations

Configuration 1 (hide)

cpe:2.3:a:esri:arcgis_server:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:50

Type Values Removed Values Added
References () https://www.esri.com/arcgis-blog/products/trust-arcgis/announcements/arcgis-server-map-and-feature-service-security-2023-update-1-patch/ - Vendor Advisory () https://www.esri.com/arcgis-blog/products/trust-arcgis/announcements/arcgis-server-map-and-feature-service-security-2023-update-1-patch/ - Vendor Advisory

08 Oct 2024, 17:15

Type Values Removed Values Added
Summary
  • (es) Las versiones 11.0 y posteriores de ArcGIS Enterprise Server presentan una vulnerabilidad de divulgación de información por la que un atacante remoto no autorizado puede enviar una consulta manipulada que puede dar lugar a un problema de divulgación de información de baja gravedad. La información revelada se limita a un único atributo en una cadena de conexión de base de datos. No se revelan datos comerciales.
Summary (en) ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthorized attacker may submit a crafted query that may result in a low severity information disclosure issue. The information disclosed is limited to a single attribute in a database connection string. No business data is disclosed. (en) ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthorized attacker may submit a crafted query that may result in a low severity information disclosure issue. The information disclosed is limited to a single attribute in a database connection string. No business data is disclosed.

Information

Published : 2023-08-25 19:15

Updated : 2024-11-21 07:50


NVD link : CVE-2023-25848

Mitre link : CVE-2023-25848

CVE.ORG link : CVE-2023-25848


JSON object : View

Products Affected

esri

  • arcgis_server
CWE
CWE-319

Cleartext Transmission of Sensitive Information