Vulnerability Description
A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify column properties in a manner that could lead to SQL injection when performed by a remote authenticated user requiring elevated, non‑administrative privileges. Exploitation is restricted to users with advanced application‑specific permissions, indicating high privileges are required. Successful exploitation would have a high impact on integrity and confidentiality, with no impact on availability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Esri | Arcgis Server | >= 10.9.1, <= 11.3 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-51962?
CVE-2024-51962 is a vulnerability with a CVSS score of 8.7 (HIGH). A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify column properties in a manner that could lead to SQL injection when performed by a remote authenticated user requiring...
How severe is CVE-2024-51962?
CVE-2024-51962 has been rated HIGH with a CVSS base score of 8.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-51962?
Check the references section above for vendor advisories and patch information. Affected products include: Esri Arcgis Server.