Show filters
109 Total Results
Displaying 71-80 of 109
Sort by:
Attacker Value
Unknown

CVE-2021-29116

Disclosure Date: December 06, 2021 (last updated February 23, 2025)
A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server feature services versions 10.8.1 and 10.9 (only) feature services may allow a remote, unauthenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the user’s browser.
Attacker Value
Unknown

CVE-2021-29113

Disclosure Date: December 06, 2021 (last updated February 23, 2025)
A remote file inclusion vulnerability in the ArcGIS Server help documentation may allow a remote, unauthenticated attacker to inject attacker supplied html into a page.
Attacker Value
Unknown

CVE-2021-29114

Disclosure Date: December 06, 2021 (last updated February 23, 2025)
A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthenticated attacker to impact the confidentiality, integrity and availability of targeted services via specifically crafted queries.
Attacker Value
Unknown

CVE-2021-29110

Disclosure Date: July 15, 2021 (last updated February 23, 2025)
Stored cross-site scripting (XSS) issue in Esri Portal for ArcGIS may allow a remote unauthenticated attacker to pass and store malicious strings in the home application.
Attacker Value
Unknown

CVE-2021-29109

Disclosure Date: July 15, 2021 (last updated February 23, 2025)
A reflected XSS vulnerability in Esri Portal for ArcGIS version 10.9 and below may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the user’s browser.
Attacker Value
Unknown

CVE-2021-29108

Disclosure Date: July 15, 2021 (last updated February 23, 2025)
There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker who is able to intercept and modify a SAML assertion to impersonate another account (XML Signature Wrapping Attack). In addition patching, Esri also strongly recommends as best practice for SAML assertions to be signed and encrypted.
0
Attacker Value
Unknown

CVE-2021-29107

Disclosure Date: July 09, 2021 (last updated February 23, 2025)
A stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote unauthenticated attacker to pass and store malicious strings in the ArcGIS Server Manager application.
Attacker Value
Unknown

CVE-2021-29106

Disclosure Date: July 09, 2021 (last updated February 23, 2025)
A reflected Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server version 10.8.1 and below may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the user’s browser.
Attacker Value
Unknown

CVE-2021-29105

Disclosure Date: July 09, 2021 (last updated February 23, 2025)
A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server Services Directory version 10.8.1 and below may allow a remote authenticated attacker to pass and store malicious strings in the ArcGIS Services Directory.
Attacker Value
Unknown

CVE-2021-29104

Disclosure Date: July 09, 2021 (last updated February 23, 2025)
A stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote unauthenticated attacker to pass and store malicious strings in the ArcGIS Server Manager application.