VYPR
High severity8.8NVD Advisory· Published Oct 1, 2021· Updated Jun 17, 2026

CVE-2021-29108

CVE-2021-29108

Description

There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker who is able to intercept and modify a SAML assertion to impersonate another account (XML Signature Wrapping Attack). In addition patching, Esri also strongly recommends as best practice for SAML assertions to be signed and encrypted.

Affected products

3
  • cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*:*range: <=10.9
    • (no CPE)range: <=10.9
    • (no CPE)range: 10.9.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.