There is a path traversal vulnerability in Esri ArcGIS...
High severity
Unreviewed
Published
Dec 28, 2022
to the GitHub Advisory Database
•
Updated Jan 30, 2023
Description
Published by the National Vulnerability Database
Dec 28, 2022
Published to the GitHub Advisory Database
Dec 28, 2022
Last updated
Jan 30, 2023
There is a path traversal vulnerability in Esri ArcGIS Server versions 10.9.1 and below. Successful exploitation may allow a remote, unauthenticated attacker traverse the file system to access files outside of the intended directory on ArcGIS Server. This could lead to the disclosure of sensitive site configuration information (not user datasets).
References