Bug:  Issues addressed by ArcGIS Server Security (August 2014) Patch

相关信息
Article ID: 41547
Bug Id: NIM102197, NIM102939
Software:
ArcGIS for Server 10.2, 10.2.1, 10.2.2, 10.1 SP1
Platforms: N/A

BUG描述
ArcGIS 10.1 SP1 QIP, 10.2.1, and 10.2.2 for Server Security (August 2014) Patch addresses two security vulnerabilities found in ArcGIS for Server.


Vulnerability details

NIM102197 - Unauthorized access to some resources from secured services is possible in certain circumstances. This occurs in ArcGIS for Server 10.2, 10.2.1, and 10.2.2

NIM102939 - Multiple stored cross-site scripting (XSS) vulnerabilities found. This occurs in ArcGIS for Server 10.1, 10.1 SP1, 10.2, 10.2.1, and 10.2.2

BUG原因
These are known issues.
已邀请:

易智瑞技术支持

赞同来自:

解决方案
There is no workaround.

Esri highly recommends that all customers using ArcGIS for Server 10.1 and later apply this patch.

Customers who are using 10.2 should first upgrade to 10.2.1 or 10.2.2.


Esri Patches and Service Packs




    创建及修改时间
    Created: 8/29/2013

    Last Modified: 9/4/2014
    原文链接
    http://support.esri.com/en/kno ... 41547

    要回复问题请先登录注册