« Volver al listado

CVE-2023-25848

Estado: ModificadaMedia (5.3)—

ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthorized attacker may submit a crafted query that may result in a low severity information disclosure issue.

The information disclosed is limited to a single attribute in a database connection string. No business data is disclosed.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-25848",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-25848",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-02T15:01:22.781949Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@esri.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@esri.com",
      "affectedData": [
        {
          "vendor": "Esri",
          "product": "ArcGIS Enterprise Server",
          "versions": [
            {
              "status": "affected",
              "version": "10.8.1"
            },
            {
              "status": "affected",
              "version": "10.9.1"
            },
            {
              "status": "affected",
              "version": "11.0"
            },
            {
              "status": "affected",
              "version": "11.1"
            }
          ],
          "platforms": [
            "x86"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-08-25T19:15:08.670",
  "references": [
    {
      "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/announcements/arcgis-server-map-and-feature-service-security-2023-update-1-patch/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@esri.com"
    },
    {
      "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/announcements/arcgis-server-map-and-feature-service-security-2023-update-1-patch/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@esri.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-319"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthorized attacker may submit a crafted query that may result in a low severity information disclosure issue. \n\nThe information disclosed is limited to a single attribute in a database connection string. No business data is disclosed."
    },
    {
      "lang": "es",
      "value": "Las versiones 11.0 y posteriores de ArcGIS Enterprise Server presentan una vulnerabilidad de divulgación de información por la que un atacante remoto no autorizado puede enviar una consulta manipulada que puede dar lugar a un problema de divulgación de información de baja gravedad. \n\nLa información revelada se limita a un único atributo en una cadena de conexión de base de datos. No se revelan datos comerciales."
    }
  ],
  "lastModified": "2026-06-17T05:42:08.277",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:esri:arcgis_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BEA722C4-4C48-4786-9720-267D7DC95095",
              "versionEndIncluding": "11.0",
              "versionStartIncluding": "10.8.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@esri.com"
}