PT-2021-18096 · Esri · Esri Portal For Arcgis

Published

2021-10-01

·

Updated

2023-09-14

·

CVE-2021-29108

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Esri Portal for ArcGIS versions 10.9 and below
Description: The issue allows a remote, authenticated attacker who is able to intercept and modify a SAML assertion to impersonate another account through an XML Signature Wrapping Attack. It is recommended as a best practice for SAML assertions to be signed and encrypted.
Recommendations: For Esri Portal for ArcGIS versions 10.9 and below, apply the recommended patch and ensure SAML assertions are signed and encrypted as a best practice to mitigate the issue.

Fix

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

CVE-2021-29108

Affected Products

Esri Portal For Arcgis