There is SQL injection vulnerability in Esri ArcGIS Insights Desktop for Mac and Windows version 2022.1 that may allow a local, authorized attacker to execute arbitrary SQL commands against the back-end database. The effort required to generate the crafted input required to exploit this issue is complex and requires significant effort before a successful attack can be expected.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-29727 | There is SQL injection vulnerability in Esri ArcGIS Insights Desktop for Mac and Windows version 2022.1 that may allow a local, authorized attacker to execute arbitrary SQL commands against the back-end database. The effort required to generate the crafted input required to exploit this issue is complex and requires significant effort before a successful attack can be expected. |
Fri, 25 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:esri:arcgis_insights:2022.1:*:*:*:*:arcgis_enterprise:*:* | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Esri
Published:
Updated: 2024-10-25T18:52:54.067Z
Reserved: 2023-02-15T17:59:31.097Z
Link: CVE-2023-25839
Updated: 2024-08-02T11:32:12.724Z
Status : Modified
Published: 2023-07-19T16:15:09.640
Modified: 2024-11-21T07:50:18.240
Link: CVE-2023-25839
No data.
OpenCVE Enrichment
No data.
EUVD