CVE-2025-57870

A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands via a specific ArcGIS Feature Service operation. Successful exploitation can potentially result in unauthorized access, modification, or deletion of data from the underlying Enterprise Geodatabase.
Configurations

No configuration.

History

22 Oct 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-22 15:15

Updated : 2025-10-22 21:12


NVD link : CVE-2025-57870

Mitre link : CVE-2025-57870

CVE.ORG link : CVE-2025-57870


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')