Esri

ArcGIS Server

69 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.94%
  • Veröffentlicht 06.07.2026 18:22:08
  • Zuletzt bearbeitet 08.07.2026 15:16:32

Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could allow overwriting...

  • EPSS 0.35%
  • Veröffentlicht 06.07.2026 18:21:11
  • Zuletzt bearbeitet 08.07.2026 16:16:35

Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload, potentially a...

  • EPSS 0.3%
  • Veröffentlicht 20.05.2026 17:51:51
  • Zuletzt bearbeitet 23.07.2026 12:10:00

ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could exploit this issue by sending a specially crafted request, Successful exploitation may result in the application redirecting the br...

  • EPSS 0.36%
  • Veröffentlicht 20.05.2026 17:47:40
  • Zuletzt bearbeitet 23.07.2026 12:10:00

ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit this issue by sending a crafted request to the endpoint. Successful exploitation may result in disru...

  • EPSS 0.21%
  • Veröffentlicht 31.12.2025 22:18:57
  • Zuletzt bearbeitet 06.01.2026 19:03:34

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context o...

  • EPSS 0.21%
  • Veröffentlicht 31.12.2025 22:18:17
  • Zuletzt bearbeitet 06.01.2026 19:04:06

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context o...

  • EPSS 0.21%
  • Veröffentlicht 31.12.2025 22:17:41
  • Zuletzt bearbeitet 06.01.2026 19:04:27

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context o...

  • EPSS 0.21%
  • Veröffentlicht 31.12.2025 22:17:08
  • Zuletzt bearbeitet 06.01.2026 19:04:52

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context o...

  • EPSS 0.26%
  • Veröffentlicht 31.12.2025 22:16:14
  • Zuletzt bearbeitet 20.02.2026 14:48:33

ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the server’s designated upload directories. However, the server’s archi...

  • EPSS 0.34%
  • Veröffentlicht 31.12.2025 22:15:44
  • Zuletzt bearbeitet 19.02.2026 21:29:24

ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the server’s designated upload directories. However, the server’s archi...