There is a local file inclusion vulnerability in ArcGIS Server 11.3 and below that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sensitive configuration information by reading internal files from the remote server.  Due to the nature of the files accessible in this vulnerability the impact to confidentiality is High there is no impact to both integrity or availability.
History

Thu, 10 Apr 2025 19:30:00 +0000

Type Values Removed Values Added
Description There is a local file inclusion vulnerability in ArcGIS Server 10.9.1 thru 11.3 that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sensitive configuration information by reading internal files from the remote server.  Due to the nature of the files accessible in this vulnerability the impact to confidentiality is High there is no impact to both integrity or availability. There is a local file inclusion vulnerability in ArcGIS Server 11.3 and below that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sensitive configuration information by reading internal files from the remote server.  Due to the nature of the files accessible in this vulnerability the impact to confidentiality is High there is no impact to both integrity or availability.

Thu, 06 Mar 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Esri
Esri arcgis Server
Weaknesses CWE-610
CPEs cpe:2.3:a:esri:arcgis_server:*:*:*:*:*:*:*:*
Vendors & Products Esri
Esri arcgis Server

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 20:15:00 +0000

Type Values Removed Values Added
Description There is a local file inclusion vulnerability in ArcGIS Server 10.9.1 thru 11.3 that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sensitive configuration information by reading internal files from the remote server.  Due to the nature of the files accessible in this vulnerability the impact to confidentiality is High there is no impact to both integrity or availability.
Title Local file inclusion (LFI) vulnerability in ArcGIS Server
Weaknesses CWE-73
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published:

Updated: 2025-04-10T19:25:47.824Z

Reserved: 2024-11-04T16:54:39.393Z

Link: CVE-2024-51961

cve-icon Vulnrichment

Updated: 2025-03-03T20:44:03.615Z

cve-icon NVD

Status : Modified

Published: 2025-03-03T20:15:42.863

Modified: 2025-04-10T20:15:21.467

Link: CVE-2024-51961

cve-icon Redhat

No data.