First published: Sun Jul 11 2021(Updated: )
A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server Services Directory version 10.8.1 and below may allow a remote authenticated attacker to pass and store malicious strings in the ArcGIS Services Directory.
Credit: psirt@esri.com
Affected Software | Affected Version | How to fix |
---|---|---|
Esri ArcGIS Server | <10.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-29105 is medium (5.4).
CVE-2021-29105 allows a remote authenticated attacker to pass and store malicious strings in the ArcGIS Services Directory.
Esri ArcGIS Server Services Directory version 10.8.1 and below are affected by CVE-2021-29105.
To fix CVE-2021-29105, apply the ArcGIS Server Security 2021 Update 1 patch provided by Esri.
Yes, you can find more information about CVE-2021-29105 and the patch at: https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/arcgis-server-security-2021-update-1-patch/