laptop and a wrench

Bug

Prevent a directory traversal malicious attack in ArcGIS GeoEvent Manager.

ArcGIS GIS Server
Bug ID Number BUG-000174297
SubmittedFebruary 12, 2025
Last ModifiedApril 24, 2025
Applies toArcGIS GIS Server
Version foundN/A
Operating SystemN/A
Operating System VersionN/A
Version Fixed11.2, 11.3, 11.4, 11.5+
StatusFixed

Additional Information

This issue is addressed in ArcGIS GeoEvent Server versions 11.2 Patch 1, 11.3 Patch 1, and 11.4 Patch 1, and is included in version 11.5.

Workaround

Use a Web Application Firewall (WAF) or web server URL re-write rules to disallow common patterns such as ../../ and other URL encoded patterns.

Steps to Reproduce

Bug ID: BUG-000174297

Software:

  • ArcGIS GIS Server

Get notified when the status of a bug changes

Download the Esri Support App

Discover more on this topic

Get help from ArcGIS experts

Contact technical support

Download the Esri Support App

Go to download options