CVE-2021-29105: There is a stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server Services Directory version 10.8.1 and below.
A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server Services Directory version 10.8.1 and below may allow a remote authenticated attacker to pass and store malicious strings in the ArcGIS Services Directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-29105?
The severity of CVE-2021-29105 is medium (5.4).
How does CVE-2021-29105 impact Esri ArcGIS Server Services Directory?
CVE-2021-29105 allows a remote authenticated attacker to pass and store malicious strings in the ArcGIS Services Directory.
Which versions of Esri ArcGIS Server Services Directory are affected by CVE-2021-29105?
Esri ArcGIS Server Services Directory version 10.8.1 and below are affected by CVE-2021-29105.
How can I fix CVE-2021-29105?
To fix CVE-2021-29105, apply the ArcGIS Server Security 2021 Update 1 patch provided by Esri.
Is there any reference for CVE-2021-29105?
Yes, you can find more information about CVE-2021-29105 and the patch at: https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/arcgis-server-security-2021-update-1-patch/