CVE-2013-5221

low
Published 2013-09-24 · Modified 2026-04-29
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

The mobile-upload feature in Esri ArcGIS for Server 10.1 through 10.2 allows remote authenticated users to upload .exe files by leveraging (1) publisher or (2) administrator privileges.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://support.esri.com/en/knowledgebase/techarticles/detail/41497

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://support.esri.com/en/downloads/patches-servicepacks/view/productid/66/metaid/2009

Application impact

VendorProductVersionsFixed
esriarcgis_server10.1
esriarcgis_server10.2

References

Verify integrity in audit chain (admin only). AS-IS.