Improper input validation in ArcGIS - #VU8827

 

Improper input validation in ArcGIS - #VU8827

Published: October 11, 2017 / Updated: October 13, 2017


Vulnerability identifier: #VU8827
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists in the configuration of the ESRI-provided ArgGIS Server image available on Azure Marketplace due to the default settings load the Java rmid service on TCP port 1098 and set the 'java.rmi.server.useCodebaseOnly' property to false. A remote attacker can send specially crafted data to cause the target RMI service to load and execute remote Java code.

Successful exploitation of the vulnerability may result in system compromise.


Affected software

ArcGIS

Remediation

The vulnerability is addressed in the following versions: 10.4.1 and 10.5.1.


External References

Related Security Bulletins