A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands via a specific ArcGIS Feature Service operation. Successful exploitation can potentially result in unauthorized access, modification, or deletion of data from the underlying Enterprise Geodatabase.
Metrics
Affected Vendors & Products
References
History
Thu, 23 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Esri
Esri arcgis Server Linux Linux linux Microsoft Microsoft windows |
|
| Vendors & Products |
Esri
Esri arcgis Server Linux Linux linux Microsoft Microsoft windows |
Wed, 22 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands via a specific ArcGIS Feature Service operation. Successful exploitation can potentially result in unauthorized access, modification, or deletion of data from the underlying Enterprise Geodatabase. | |
| Title | BUG-000179884 - There is a security vulnerability in ArcGIS Server Feature Services. | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Esri
Published: 2025-10-22T14:26:22.857Z
Updated: 2025-10-23T03:55:33.519Z
Reserved: 2025-08-21T19:31:57.229Z
Link: CVE-2025-57870
Updated: 2025-10-22T15:37:43.966Z
Status : Awaiting Analysis
Published: 2025-10-22T15:15:51.830
Modified: 2025-10-22T21:12:32.330
Link: CVE-2025-57870
No data.
ReportizFlow