Home
MEDIUM: 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:LDefault status
unaffected
10.9.1 (custom)
affected
Description
ArcGIS Server version 11.5 and earlier on Windows and Linux does not properly validate uploaded files file, which allows remote attackers to upload arbitrary files.
Problem types
CWE-434 Unrestricted Upload of File with Dangerous Type
Product status
10.9.1 (custom)
References
www.esri.com/...n/arcgis-server-security-2025-update-2-patch
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.