A SQL injection vulnerability exists in some configurations of Esri ArcGIS Server versions 10.8.1 (and earlier). Specially crafted web requests can expose information that is not intended to be disclosed (not customer datasets).
- Web Services that use file based data sources (file Geodatabase or Shape Files or tile cached services) are unaffected by this issue.
- By default, services published to ArcGIS Enterprise are not available anonymously and those services cannot be accessed by an unauthenticated attacker.
- Database accounts should be configured using the principle of least privilege.
Esri has released updates for ArcGIS Server that resolve this moderate-risk vulnerability here.
CVSS and CVE (Coming soon)
- Elwood Buck (MindPoint Group)
- Peter Davies (MindPoint Group)