VYPR
Critical severity9.8NVD Advisory· Published Dec 7, 2021· Updated Jun 17, 2026

CVE-2021-29114

CVE-2021-29114

Description

A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthenticated attacker to impact the confidentiality, integrity and availability of targeted services via specifically crafted queries.

Affected products

3
  • Esri/Arcgis Servercpe-rescue3 versions
    All+ 2 more
    • (no CPE)range: All
    • (no CPE)range: <=10.9
    • cpe:2.3:a:esri:arcgis_server:*:*:*:*:*:*:*:*range: <=10.9.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.