VYPR
Medium severity6.1NVD Advisory· Published Oct 25, 2022· Updated Jun 17, 2026

CVE-2022-38199

CVE-2022-38199

Description

A remote file download issue can occur in some capabilities of Esri ArcGIS Server web services that may in some edge cases allow a remote, unauthenticated attacker to induce an unsuspecting victim to launch a process in the victim's PATH environment. Current browsers provide users with warnings against running unsigned executables downloaded from the internet.

Affected products

5
  • Esri/Arcgis Serverllm-fuzzy5 versions
    (expand)+ 4 more
    • (no CPE)
    • (no CPE)range: All
    • cpe:2.3:a:esri:arcgis_server:10.7.1:*:*:*:*:*:x64:*
    • cpe:2.3:a:esri:arcgis_server:10.8.1:*:*:*:*:*:x64:*
    • cpe:2.3:a:esri:arcgis_server:10.9.1:*:*:*:*:*:x64:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.