LiveActive security incident?Get immediate response
CVE Record

CVE-2021-29114: SQL injection vulnerability in ArcGIS Server

A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthenticated attacker to impact the confidentiality, integrity and availability of targeted services via specifically crafted queries.

HighCVSS 7.3Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

ArcGIS Server feature services in versions 10.9 and below have a SQL injection flaw. An unauthenticated remote attacker could affect confidentiality, integrity, and availability of targeted services through crafted queries. The issue is high priority for organizations exposing ArcGIS services externally.

Executive priority

Treat as a high-priority remediation item where ArcGIS Server feature services are exposed. The business risk is unauthorized access or disruption to GIS-backed services, without needing credentials or user interaction.

Technical view

CVE-2021-29114 is a CWE-89 SQL injection vulnerability in Esri ArcGIS Server feature services. The CVSS 3.0 score is 7.3 with network attack vector, low complexity, no privileges, and no user interaction required. Impact is rated low for confidentiality, integrity, and availability.

Likely exposure

Most likely exposure is internet-facing or partner-accessible ArcGIS Server feature services running 10.9 or below. Internal-only deployments still matter if untrusted users or compromised hosts can reach the services.

Exploitation context

The provided sources do not state active exploitation, and the CVE is not marked as CISA KEV. The vulnerability is still serious because it is remotely reachable, unauthenticated, and low complexity according to the CVSS vector.

Researcher notes

The source bundle identifies ArcGIS Server 10.9 and below feature services and SQL injection behavior, but does not include detailed patch applicability or exploit indicators. Avoid assuming broader Esri product impact beyond ArcGIS Server feature services.

Mitigation direction

  • Inventory ArcGIS Server deployments and identify versions 10.9 and below.
  • Review Esri’s ArcGIS Server Security 2021 Update 2 Patch guidance.
  • Apply the Esri patch where applicable, following vendor instructions.
  • Reduce unauthenticated access to feature services until remediation is confirmed.
  • Prioritize externally reachable services before internal-only systems.

Validation and detection

  • Confirm each ArcGIS Server version and patch level against Esri guidance.
  • Identify exposed feature services and their network accessibility.
  • Verify patched systems no longer match the affected version state.
  • Review logs for unusual query activity against feature services.
  • Document any unpatched instances with owner, exposure, and remediation date.
Prepared
Confidence
high
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-89: Database access and collection lookup

Injection into data stores can inform collection, data access, and exfiltration detection reviews. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Database behavior lookup

The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-29114 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.3 (3.0)
Known Exploited
No
Published

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.3CVSS 3.0HighCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L3.93.4Primary CVE score

Vulnerability scoring details

Base CVSS 3.0 score

7.3High
CVSS 3.0 vector shape for CVE-2021-29114Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
EsriArcGIS ServerAllListed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.