6.1
CVSSv3

CVE-2022-38199

Published: 25/10/2022 Updated: 28/10/2022
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A remote file download issue can occur in some capabilities of Esri ArcGIS Server web services that may in some edge cases allow a remote, unauthenticated malicious user to induce an unsuspecting victim to launch a process in the victim's PATH environment. Current browsers provide users with warnings against running unsigned executables downloaded from the internet.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

esri arcgis server 10.7.1

esri arcgis server 10.8.1

esri arcgis server 10.9.1