VYPR
Medium severity5.3NVD Advisory· Published Dec 7, 2021· Updated Jun 17, 2026

CVE-2021-29115

CVE-2021-29115

Description

An information disclosure vulnerability in the ArcGIS Service Directory in Esri ArcGIS Enterprise versions 10.9.0 and below may allows a remote attacker to view hidden field names in feature layers. This issue may reveal field names, but not not disclose features.

Affected products

3
  • cpe:2.3:a:esri:arcgis_enterprise:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:esri:arcgis_enterprise:*:*:*:*:*:*:*:*range: <=10.9
    • (no CPE)range: <=10.9.0
  • Range: All

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.