There is an improper access control issue in ArcGIS Server versions 10.9.1 through 11.3 on Windows and Linux, which under unique circumstances, could potentially allow a remote, low privileged authenticated attacker to access secure services published a standalone (Unfederated) ArcGIS Server instance.  If successful this compromise would have a high impact on Confidentiality, low impact on integrity and no impact to availability of the software.
History

Thu, 06 Mar 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Esri
Esri arcgis Server
Linux
Linux linux Kernel
Microsoft
Microsoft windows
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:esri:arcgis_server:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Esri
Esri arcgis Server
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 20:00:00 +0000

Type Values Removed Values Added
Description There is an improper access control issue in ArcGIS Server versions 10.9.1 through 11.3 on Windows and Linux, which under unique circumstances, could potentially allow a remote, low privileged authenticated attacker to access secure services published a standalone (Unfederated) ArcGIS Server instance.  If successful this compromise would have a high impact on Confidentiality, low impact on integrity and no impact to availability of the software.
Title Unauthorized access to secure services in ArcGIS Server
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published: 2025-03-03T19:53:21.215Z

Updated: 2025-03-03T20:44:42.818Z

Reserved: 2024-11-04T16:54:39.392Z

Link: CVE-2024-51954

cve-icon Vulnrichment

Updated: 2025-03-03T20:43:05.776Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-03T20:15:41.903

Modified: 2025-03-06T14:23:26.167

Link: CVE-2024-51954

cve-icon Redhat

No data.