CVE-2021-29099
ArcGIS Server vulnerability analysis and mitigation

Overview

A SQL injection vulnerability (CVE-2021-29099) was identified in certain configurations of ArcGIS Server versions 10.8.1 and earlier. The vulnerability was discovered and disclosed by March 31, 2021, affecting Esri ArcGIS Server installations. This security flaw allows specially crafted web requests to potentially expose unintended information, though notably not customer datasets (Esri Blog).

Technical details

The vulnerability is classified as CWE-89 (SQL Injection) with a CVSS v3.1 Base Score of 5.3 and a Temporal Score of 4.8. The technical assessment indicates proof-of-concept exploit code maturity, with official fixes available and the vulnerability confirmed by Esri. The CVSS vector string is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N (Esri Blog).

Impact

The vulnerability's impact is primarily focused on information disclosure, though it specifically does not affect customer datasets. The moderate-risk vulnerability received a CVSS base score of 5.3, indicating a relatively moderate severity level (Esri Blog).

Mitigation and workarounds

Several mitigation measures are available: Web Services using file-based data sources (file Geodatabase, Shape Files, or tile cached services) are unaffected. By default, services published to ArcGIS Enterprise are not available anonymously, preventing unauthenticated attacks. It's recommended to configure database accounts using the principle of least privilege. Esri has released official updates for ArcGIS Server to resolve this vulnerability (Esri Blog).

Community reactions

The vulnerability was responsibly disclosed with acknowledgments to security researchers Elwood Buck and Peter Davies from MindPoint Group who discovered the vulnerability (Esri Blog).

Additional resources


SourceThis report was generated using AI

Related ArcGIS Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-57870CRITICAL10
  • ArcGIS ServerArcGIS Server
  • cpe:2.3:a:esri:arcgis_server
NoYesOct 22, 2025
CVE-2024-51962CRITICAL9.6
  • ArcGIS ServerArcGIS Server
  • cpe:2.3:a:esri:arcgis_server
NoYesMar 03, 2025
CVE-2024-51966MEDIUM4.9
  • ArcGIS ServerArcGIS Server
  • cpe:2.3:a:esri:arcgis_server
NoYesMar 03, 2025
CVE-2024-5888MEDIUM4.8
  • ArcGIS ServerArcGIS Server
  • cpe:2.3:a:esri:arcgis_server
NoYesMar 03, 2025
CVE-2024-51963MEDIUM4.8
  • ArcGIS ServerArcGIS Server
  • cpe:2.3:a:esri:arcgis_server
NoYesMar 03, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management