Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 31 Oct 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kubernetes
Kubernetes kubernetes Linux linux Kernel |
|
| CPEs | cpe:2.3:a:esri:arcgis_server:*:*:*:*:*:*:*:* cpe:2.3:a:kubernetes:kubernetes:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Kubernetes
Kubernetes kubernetes Linux linux Kernel |
Thu, 23 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Esri
Esri arcgis Server Linux Linux linux Microsoft Microsoft windows |
|
| Vendors & Products |
Esri
Esri arcgis Server Linux Linux linux Microsoft Microsoft windows |
Wed, 22 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands via a specific ArcGIS Feature Service operation. Successful exploitation can potentially result in unauthorized access, modification, or deletion of data from the underlying Enterprise Geodatabase. | |
| Title | BUG-000179884 - There is a security vulnerability in ArcGIS Server Feature Services. | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Esri
Published:
Updated: 2026-02-26T16:57:13.694Z
Reserved: 2025-08-21T19:31:57.229Z
Link: CVE-2025-57870
Updated: 2025-10-22T15:37:43.966Z
Status : Analyzed
Published: 2025-10-22T15:15:51.830
Modified: 2025-10-31T18:51:22.923
Link: CVE-2025-57870
No data.
OpenCVE Enrichment
Updated: 2025-10-23T10:04:48Z