Executive brief
ArcGIS Server is a geospatial data and mapping platform used by organizations to publish and manage geographic information. Versions 11.5 and earlier contain a file upload validation flaw that allows unauthenticated attackers to upload arbitrary files to designated directories. While the server architecture prevents these files from being executed or used to compromise the system, the vulnerability still represents an unauthorized storage footprint that could support further attacks or compliance violations.
Technical details
The vulnerability is an insufficient file upload validation issue in ArcGIS Server versions 11.5 and earlier on Windows and Linux platforms. An unauthenticated, network-accessible attacker can upload arbitrary files to the server's designated upload directories without proper validation. However, the server's architectural controls restrict uploaded files to non-executable storage locations and prevent modification of application components or system configuration, and uploaded files cannot be executed or used to access sensitive data. Exploitation may require race conditions, knowledge of secret values, or man-in-the-middle conditions. The issue is classified as low-impact on confidentiality, integrity, and availability.
Affected products
- Esri ArcGIS Server 11.5 and earlier
Timeline
- 2025-12-31: disclosed