An information disclosure vulnerability in the ArcGIS Service Directory in Esri ArcGIS Enterprise versions 10.9.0 and below may allows a remote attacker to view hidden field names in feature layers. This issue may reveal field names, but not not disclose features.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-15756 | An information disclosure vulnerability in the ArcGIS Service Directory in Esri ArcGIS Enterprise versions 10.9.0 and below may allows a remote attacker to view hidden field names in feature layers. This issue may reveal field names, but not not disclose features. |
Fixes
Solution
No solution given by the vendor.
Workaround
Options to address this issue include securing the hosted feature service and any created views.
References
History
Thu, 10 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Esri
Published:
Updated: 2025-04-10T14:59:02.069Z
Reserved: 2021-03-23T00:00:00.000Z
Link: CVE-2021-29115
Updated: 2024-08-03T22:02:50.331Z
Status : Modified
Published: 2021-12-07T11:15:07.967
Modified: 2024-11-21T06:00:44.823
Link: CVE-2021-29115
No data.
OpenCVE Enrichment
No data.
EUVD