Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-15749 | There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker who is able to intercept and modify a SAML assertion to impersonate another account (XML Signature Wrapping Attack). In addition patching, Esri also strongly recommends as best practice for SAML assertions to be signed and encrypted. |
Solution
https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/Portal-for-ArcGIS-Securit... https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/Portal-for-ArcGIS-Security-2021-Update-1-Patch
Workaround
Always encrypt and sign SAML assertions.
Thu, 10 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Esri
Published:
Updated: 2025-04-10T14:59:54.052Z
Reserved: 2021-03-23T00:00:00.000Z
Link: CVE-2021-29108
Updated: 2024-08-03T22:02:50.492Z
Status : Modified
Published: 2021-10-01T15:15:07.697
Modified: 2024-11-21T06:00:44.067
Link: CVE-2021-29108
No data.
OpenCVE Enrichment
No data.
EUVD