Learn about CVE-2020-35712 affecting Esri ArcGIS Server before version 10.8, allowing SSRF attacks. Find mitigation steps and prevention measures to secure systems.
Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations.
Understanding CVE-2020-35712
Esri ArcGIS Server is susceptible to Server-Side Request Forgery (SSRF) in specific setups.
What is CVE-2020-35712?
This CVE identifies a security flaw in Esri ArcGIS Server versions prior to 10.8 that allows attackers to perform SSRF attacks under certain conditions.
The Impact of CVE-2020-35712
The vulnerability could be exploited by malicious actors to send unauthorized requests from the server, potentially leading to unauthorized access to internal systems or data leakage.
Technical Details of CVE-2020-35712
Esri ArcGIS Server SSRF Vulnerability
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Steps to Secure Systems Against CVE-2020-35712
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates