CVE-2022-38199
BUG-000144172 - Remote file download issue in ArcGIS Server
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A remote file download issue can occur in some capabilities of Esri ArcGIS Server web services that may in some edge cases allow a remote, unauthenticated attacker to induce an unsuspecting victim to launch a process in the victim's PATH environment. Current browsers provide users with warnings against running unsigned executables downloaded from the internet.
Puede producirse un problema de descarga remota de archivos en algunas capacidades de los servicios web de Esri ArcGIS Server que, en algunos casos extremos, puede permitir a un atacante remoto no autenticado inducir a una víctima desprevenida a iniciar un proceso en el entorno PATH de la víctima. Los navegadores actuales proporcionan a usuarios advertencias contra la ejecución de ejecutables no firmados descargados de Internet
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-08-12 CVE Reserved
- 2022-10-25 CVE Published
- 2024-03-09 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-494: Download of Code Without Integrity Check
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Esri Search vendor "Esri" | Arcgis Server Search vendor "Esri" for product "Arcgis Server" | 10.7.1 Search vendor "Esri" for product "Arcgis Server" and version "10.7.1" | x64 |
Affected
| ||||||
Esri Search vendor "Esri" | Arcgis Server Search vendor "Esri" for product "Arcgis Server" | 10.8.1 Search vendor "Esri" for product "Arcgis Server" and version "10.8.1" | x64 |
Affected
| ||||||
Esri Search vendor "Esri" | Arcgis Server Search vendor "Esri" for product "Arcgis Server" | 10.9.1 Search vendor "Esri" for product "Arcgis Server" and version "10.9.1" | x64 |
Affected
|