Vulnerabilities > Esri > Arcgis Server > 10.9.1

DATE CVE VULNERABILITY TITLE RISK
2025-03-03 CVE-2024-10904 Cross-site Scripting vulnerability in Esri Arcgis Server 10.9.1/11.1
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
network
low complexity
esri CWE-79
4.8
2025-03-03 CVE-2024-51942 Cross-site Scripting vulnerability in Esri Arcgis Server 10.9.1/11.1
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
network
low complexity
esri CWE-79
4.8
2025-03-03 CVE-2024-51944 Cross-site Scripting vulnerability in Esri Arcgis Server 10.9.1/11.1
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
network
low complexity
esri CWE-79
4.8
2025-03-03 CVE-2024-51954 Improper Access Control vulnerability in Esri Arcgis Server 10.9.1/11.1
There is an improper access control issue in ArcGIS Server versions 10.9.1 through 11.3 on Windows and Linux, which under unique circumstances, could potentially allow a remote, low privileged authenticated attacker to access secure services published a standalone (Unfederated) ArcGIS Server instance.  If successful this compromise would have a high impact on Confidentiality, low impact on integrity and no impact to availability of the software.
network
low complexity
esri CWE-284
7.1
2025-03-03 CVE-2024-51958 Path Traversal vulnerability in Esri Arcgis Server 10.9.1/11.1
There is a path traversal vulnerability in ESRI ArcGIS Server versions 10.9.1 thru 11.3.
network
low complexity
esri CWE-22
4.9
2025-03-03 CVE-2024-51961 External Control of File Name or Path vulnerability in Esri Arcgis Server 10.9.1/11.1
There is a local file inclusion vulnerability in ArcGIS Server 10.9.1 thru 11.3 that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sensitive configuration information by reading internal files from the remote server.  Due to the nature of the files accessible in this vulnerability the impact to confidentiality is High there is no impact to both integrity or availability.
network
low complexity
esri CWE-73
7.5
2025-03-03 CVE-2024-51962 SQL Injection vulnerability in Esri Arcgis Server 10.9.1/11.1
A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify Column properties allowing for the execution of a SQL Injection by a remote authenticated user with elevated (non admin) privileges.  There is a high impact to integrity and confidentiality and no impact to availability.
network
low complexity
esri CWE-89
critical
9.6
2025-03-03 CVE-2024-51966 Path Traversal vulnerability in Esri Arcgis Server 10.9.1/11.1
There is a path traversal vulnerability in ESRI ArcGIS Server versions 10.9.1 thru 11.3.
network
low complexity
esri CWE-22
4.9
2023-07-21 CVE-2023-25840 Unspecified vulnerability in Esri Arcgis Server 10.8.1/10.9.0/10.9.1
There is a Cross-site Scripting vulnerability in ArcGIS Server in versions 10.8.1 – 11.1 that may allow a remote, authenticated attacker to create a crafted link which onmouseover wont execute but could potentially render an image in the victims browser.
network
low complexity
esri
3.4
2022-12-28 CVE-2022-38202 Path Traversal vulnerability in Esri Arcgis Server
There is a path traversal vulnerability in Esri ArcGIS Server versions 10.9.1 and below.
network
low complexity
esri CWE-22
7.5