Vulnerability of ArcGIS Server: SQL injection

Synthesis of the vulnerability

An attacker can use a SQL injection in ArcGIS Server, in order to read or alter data.
Severity of this threat: 2/4.
Creation date: 15/05/2013.
Références of this weakness: NIM084249, VIGILANCE-VUL-12830.

Description of the vulnerability

The ArcGIS Server product allows users to perform a search on maps.

However, user's data are directly inserted in a SQL query.

An attacker can therefore use a SQL injection in ArcGIS Server, in order to read or alter data.
This security announce impacts software or systems such as ArcGIS ArcView, ArcGIS for Desktop, ArcGIS for Server.

Our Vigil@nce team determined that the severity of this threat is medium.

The trust level is of type confirmed by the editor, with an origin of user account.

An attacker with a expert ability can exploit this computer vulnerability announce.

Solutions for this threat

ArcGIS Server: patch.
A patch is available in information sources.
Computer vulnerabilities tracking service

