Esri ArcGIS Monitor SQL Injection Vulnerability Allowing Database Schema Enumeration

Vulnerability

A SQL injection vulnerability has been identified in Esri ArcGIS Monitor versions 2023.0 prior to 2024.x, on both Windows and Linux. This vulnerability allows remote, authenticated attackers with low privileges to improperly access limited database schema information by sending crafted queries. While it is possible to enumerate some internal database identifiers, the risk to confidentiality is considered low, as any sensitive data retrieved is encrypted. There is no known impact on integrity or availability.

Impact

Exploitation of this vulnerability could lead to unauthorized access to certain database schema information, including internal database identifiers, which could be misused in conjunction with other vulnerabilities or information to escalate privileges or cause harm to the system.

Remediation

Users can upgrade to ArcGIS Monitor version 2024.1 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.