CVE-2021-29113

A remote file inclusion vulnerability in the ArcGIS Server help documentation may allow a remote, unauthenticated attacker to inject attacker supplied html into a page.
Configurations

Configuration 1 (hide)

cpe:2.3:a:esri:arcgis_server:*:*:*:*:*:*:x64:*

History

02 Aug 2022, 15:57

Type Values Removed Values Added
CWE CWE-94 CWE-829

30 Mar 2022, 13:45

Type Values Removed Values Added
CPE cpe:2.3:a:esri:arcgis_server:-:*:*:*:*:*:*:* cpe:2.3:a:esri:arcgis_server:*:*:*:*:*:*:x64:*
References (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/arcgis-server-security-2021-update-2-patch-is-now-available - Vendor Advisory (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/arcgis-server-security-2021-update-2-patch-is-now-available - Not Applicable, Vendor Advisory

08 Dec 2021, 14:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 4.7
References (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/arcgis-server-security-2021-update-2-patch-is-now-available - (CONFIRM) https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/arcgis-server-security-2021-update-2-patch-is-now-available - Vendor Advisory
CWE CWE-94
CPE cpe:2.3:a:esri:arcgis_server:-:*:*:*:*:*:*:*

07 Dec 2021, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-12-07 11:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-29113

Mitre link : CVE-2021-29113

CVE.ORG link : CVE-2021-29113


JSON object : View

Products Affected

esri

  • arcgis_server
CWE
CWE-829

Inclusion of Functionality from Untrusted Control Sphere

CWE-98

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')