Vulnerability Details CVE-2024-51962
A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify Column properties allowing for the execution of a SQL Injection by a remote authenticated user with elevated (non admin) privileges. There is a high impact to integrity and confidentiality and no impact to availability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 27.0%
CVSS Severity
CVSS v3 Score 8.7
Products affected by CVE-2024-51962
-
cpe:2.3:a:esri:arcgis_server:10.9.1
-
cpe:2.3:a:esri:arcgis_server:11.0
-
cpe:2.3:a:esri:arcgis_server:11.1
-
cpe:2.3:a:esri:arcgis_server:11.2
-
cpe:2.3:a:esri:arcgis_server:11.3