CVE-2021-29108
01.10.2021, 15:15
There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker who is able to intercept and modify a SAML assertion to impersonate another account (XML Signature Wrapping Attack). In addition patching, Esri also strongly recommends as best practice for SAML assertions to be signed and encrypted.Enginsight
Vendor | Product | Version |
---|---|---|
esri | portal_for_arcgis | 𝑥 ≤ 10.9 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References