<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ArcGIS Server 10.8.1 and port 8081 running Apache Spark 2.4.4? in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-server-10-8-1-and-port-8081-running-apache/m-p/1089325#M30924</link>
    <description>&lt;P&gt;The bundled jquery version is 1.12.4 and anything below 3.5.0 is susceptible to XSS attacks.&amp;nbsp; Installing security patches did not fix the issue...&lt;/P&gt;&lt;P&gt;Apparently the version of jquery triggering a vulnerability to our security scan is contained in&amp;nbsp;&lt;/P&gt;&lt;P&gt;C:\Program Files\ArcGIS\Server\framework\runtime\spark\jars\spark-core_2.11-2.4.4.jar&lt;/P&gt;&lt;P&gt;C:\Program Files\ArcGIS\Server\framework\lib\shared\hadoop-yarn-common-2.7.3.jar &amp;nbsp;&lt;/P&gt;&lt;P&gt;C:\Program Files\ArcGIS\Server\framework\lib\shared\scala-compiler-2.11.12.jar&amp;nbsp;&lt;/P&gt;&lt;P&gt;C:\Program Files\ArcGIS\Server\framework\lib\shared\spark-core_2.11-2.4.4.jar&lt;/P&gt;&lt;P&gt;C:\Program Files\ArcGIS\Server\framework\runtime\spark\jars\Hadoop-yarn-common-2.9.2.jar&lt;/P&gt;&lt;P&gt;C:\Program Files\ArcGIS\Server\framework\runtime\spark\jars\scala-compiler-2.11.12.jar&lt;/P&gt;</description>
    <pubDate>Mon, 16 Aug 2021 15:54:00 GMT</pubDate>
    <dc:creator>Jay_Gregory</dc:creator>
    <dc:date>2021-08-16T15:54:00Z</dc:date>
    <item>
      <title>ArcGIS Server 10.8.1 and port 8081 running Apache Spark 2.4.4?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-server-10-8-1-and-port-8081-running-apache/m-p/1089317#M30923</link>
      <description>&lt;P&gt;I am running ArcGIS Server 10.8.1 on a local server (WS 2016), and have noticed Apache Spark running on port 8081 (http).&amp;nbsp; Our security scan picked it up because there is an older version of JQuery bundled with whatever site is on that port.&amp;nbsp; We opened a case with tech support, who claimed it had nothing to do with Esri because ArcGIS Server does not use port 8081 (it is certainly not listed in the documentation).&amp;nbsp; However, if I turn off ArcGIS Server service in windows service manager, the 8081 Apache Spark site goes down, so I assume it has something to do with ArcGIS Server (as the accessibility of the site is tied to whether ArcGIS Server service is running or not)&lt;/P&gt;&lt;P&gt;There is no other Esri software installed on that server.&amp;nbsp; Our security configuration for server is https only, tls1.1 and 1.2, and HSTS enabled.&amp;nbsp; Can anyone shed any light on this - I can find nothing in the documentation about Apache Spark or port 8081 being used with ArcGIS Server.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;I am running ArcGIS Server 10.6.1 on different servers and do not see this issue there.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 16:07:51 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-server-10-8-1-and-port-8081-running-apache/m-p/1089317#M30923</guid>
      <dc:creator>Jay_Gregory</dc:creator>
      <dc:date>2021-08-16T16:07:51Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Server 10.8.1 and port 8081 running Apache Spark 2.4.4?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-server-10-8-1-and-port-8081-running-apache/m-p/1089325#M30924</link>
      <description>&lt;P&gt;The bundled jquery version is 1.12.4 and anything below 3.5.0 is susceptible to XSS attacks.&amp;nbsp; Installing security patches did not fix the issue...&lt;/P&gt;&lt;P&gt;Apparently the version of jquery triggering a vulnerability to our security scan is contained in&amp;nbsp;&lt;/P&gt;&lt;P&gt;C:\Program Files\ArcGIS\Server\framework\runtime\spark\jars\spark-core_2.11-2.4.4.jar&lt;/P&gt;&lt;P&gt;C:\Program Files\ArcGIS\Server\framework\lib\shared\hadoop-yarn-common-2.7.3.jar &amp;nbsp;&lt;/P&gt;&lt;P&gt;C:\Program Files\ArcGIS\Server\framework\lib\shared\scala-compiler-2.11.12.jar&amp;nbsp;&lt;/P&gt;&lt;P&gt;C:\Program Files\ArcGIS\Server\framework\lib\shared\spark-core_2.11-2.4.4.jar&lt;/P&gt;&lt;P&gt;C:\Program Files\ArcGIS\Server\framework\runtime\spark\jars\Hadoop-yarn-common-2.9.2.jar&lt;/P&gt;&lt;P&gt;C:\Program Files\ArcGIS\Server\framework\runtime\spark\jars\scala-compiler-2.11.12.jar&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 15:54:00 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-server-10-8-1-and-port-8081-running-apache/m-p/1089325#M30924</guid>
      <dc:creator>Jay_Gregory</dc:creator>
      <dc:date>2021-08-16T15:54:00Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Server 10.8.1 and port 8081 running Apache Spark 2.4.4?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-server-10-8-1-and-port-8081-running-apache/m-p/1089497#M30930</link>
      <description>&lt;P&gt;Interestingly I cannot find anything listening on 8081 within our 10.8.1 Enterprise.&lt;/P&gt;&lt;P&gt;As outlined in the microsoft doco, there is a bunch of best practise you can use to mitigate this risk. &lt;A href="https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-firewall/best-practices-configuring" target="_blank"&gt;https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-firewall/best-practices-configuring&lt;/A&gt;.&amp;nbsp;Ensure your security review considers mitigating mechanisms and is not clear-cut with compliant/non-compliant.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a FYI, I would recommend you install the ArcGIS software to the D drive and leave C to the OS. E drive can then store the site information (e.g. arcgis server directories).&lt;/P&gt;</description>
      <pubDate>Tue, 17 Aug 2021 03:22:14 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-server-10-8-1-and-port-8081-running-apache/m-p/1089497#M30930</guid>
      <dc:creator>AngusHooper1</dc:creator>
      <dc:date>2021-08-17T03:22:14Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Server 10.8.1 and port 8081 running Apache Spark 2.4.4?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-server-10-8-1-and-port-8081-running-apache/m-p/1090188#M30953</link>
      <description>&lt;P&gt;Do you have GeoAnalytics configured? I think it is related to GeoAnalytics and is the Spark UI. I'd reach back out to Tech Support and have them test on their own environment with GeoAnalytics.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 22:49:38 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-server-10-8-1-and-port-8081-running-apache/m-p/1090188#M30953</guid>
      <dc:creator>JonathanQuinn</dc:creator>
      <dc:date>2021-08-18T22:49:38Z</dc:date>
    </item>
  </channel>
</rss>

