CVE-2023-25848
25.08.2023, 19:15
ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthorized attacker may submit a crafted query that may result in a low severity information disclosure issue. The information disclosed is limited to a single attribute in a database connection string. No business data is disclosed.Enginsight
Vendor | Product | Version |
---|---|---|
esri | arcgis_server | 10.8.1 ≤ 𝑥 ≤ 11.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration