ArcGIS Server Manager SSRF Vulnerability

ArcGIS Server Manager SSRF Vulnerability

CVE-2021-29102 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

A Server-Side Request Forgery (SSRF) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote, unauthenticated attacker to forge GET requests to arbitrary URLs from the system, potentially leading to network enumeration or facilitating other attacks.

Learn more about our Cis Benchmark Audit For Server Software.