CVE-2021-29115 MEDIUM

CVE-2021-29115: An information disclosure vulnerability

Vendor Esri
Product ArcGIS Server
Weakness CWE-200 · Info exposure
Published December 7, 2021
Last update April 10, 2025

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

An information disclosure vulnerability in the ArcGIS Service Directory in Esri ArcGIS Enterprise versions 10.9.0 and below may allows a remote attacker to view hidden field names in feature layers. This issue may reveal field names, but not not disclose features.

Key dates

02Disclosure timeline

December 7, 2021 CVE published
April 10, 2025 Record updated