Description
A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify column properties in a manner that could lead to SQL injection when performed by a remote authenticated user requiring elevated, non‑administrative privileges. Exploitation is restricted to users with advanced application‑specific permissions, indicating high privileges are required. Successful exploitation would have a high impact on integrity and confidentiality, with no impact on availability.
Published: 2025-03-03
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Install ArcGIS Server security 2025 update 1.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5530 A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify Column properties allowing for the execution of a SQL Injection by a remote authenticated user with elevated (non admin) privileges.  There is a high impact to integrity and confidentiality and no impact to availability.
History

Fri, 06 Feb 2026 06:30:00 +0000

Type Values Removed Values Added
Description A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify Column properties allowing for the execution of a SQL Injection by a remote authenticated user with elevated (non admin) privileges.  There is a high impact to integrity and confidentiality and no impact to availability. A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify column properties in a manner that could lead to SQL injection when performed by a remote authenticated user requiring elevated, non‑administrative privileges. Exploitation is restricted to users with advanced application‑specific permissions, indicating high privileges are required. Successful exploitation would have a high impact on integrity and confidentiality, with no impact on availability.

Thu, 06 Mar 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Esri
Esri arcgis Server
CPEs cpe:2.3:a:esri:arcgis_server:*:*:*:*:*:*:*:*
Vendors & Products Esri
Esri arcgis Server

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 20:15:00 +0000

Type Values Removed Values Added
Description A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify Column properties allowing for the execution of a SQL Injection by a remote authenticated user with elevated (non admin) privileges.  There is a high impact to integrity and confidentiality and no impact to availability.
Title SQL injection vulnerability in ArcGIS Server
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Esri Arcgis Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published:

Updated: 2026-02-06T06:08:07.932Z

Reserved: 2024-11-04T16:54:40.930Z

Link: CVE-2024-51962

cve-icon Vulnrichment

Updated: 2025-03-03T20:35:28.404Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-03T20:15:43.043

Modified: 2026-02-13T19:41:49.147

Link: CVE-2024-51962

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses