There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker who is able to intercept and modify a SAML assertion to impersonate another account (XML Signature Wrapping Attack). In addition patching, Esri also strongly recommends as best practice for SAML assertions to be signed and encrypted.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: Esri
Published:
Updated: 2024-09-16T16:48:34.344Z
Reserved: 2021-03-23T00:00:00
Link: CVE-2021-29108

No data.

Status : Modified
Published: 2021-10-01T15:15:07.697
Modified: 2024-11-21T06:00:44.067
Link: CVE-2021-29108

No data.