Vulnerability Details CVE-2024-25693
There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authenticated attacker to traverse the file system to access files or execute code outside of the intended directory.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.118
EPSS Ranking 93.4%
CVSS Severity
CVSS v3 Score 9.9
Products affected by CVE-2024-25693
-
cpe:2.3:a:esri:portal_for_arcgis:-
-
cpe:2.3:a:esri:portal_for_arcgis:10.6
-
cpe:2.3:a:esri:portal_for_arcgis:10.6.1
-
cpe:2.3:a:esri:portal_for_arcgis:10.7.1
-
cpe:2.3:a:esri:portal_for_arcgis:10.8
-
cpe:2.3:a:esri:portal_for_arcgis:10.8.1
-
cpe:2.3:a:esri:portal_for_arcgis:10.9
-
cpe:2.3:a:esri:portal_for_arcgis:10.9.1
-
cpe:2.3:a:esri:portal_for_arcgis:11.0
-
cpe:2.3:a:esri:portal_for_arcgis:11.1
-
cpe:2.3:a:esri:portal_for_arcgis:11.2
-
cpe:2.3:o:linux:linux_kernel:-
-
cpe:2.3:o:microsoft:windows:-