← back
CVE-2021-29114highCWE-89

SQL injection vulnerability in ArcGIS Server

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.3epss 1.0%
exploitation probability
1.0%top 39% of all CVEs
observed exploitation
nono source reports it
In short

ArcGIS Server versions 10.9 and below have a SQL injection flaw in their feature services that lets attackers send specially crafted requests to steal, modify, or delete database information without needing to log in.

Technical detail

SQL injection vulnerability in ArcGIS Server feature services (v10.9 and below) allows unauthenticated remote attackers to execute arbitrary SQL commands through maliciously crafted queries, compromising confidentiality, integrity, and availability of backend databases.

Summary generated and translated by AI from the official description.
A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthenticated attacker to impact the confidentiality, integrity and availability of targeted services via specifically crafted queries.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected products
Esri · ArcGIS Server