<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ArcGIS Portal patching order? in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-portal-patching-order/m-p/1146927#M32496</link>
    <description>&lt;P&gt;Security patches for different products are released at different frequencies, so you shouldn't have any problem with installing the Portal for ArcGIS security patch following the installation of the ArcGIS Server security patch.&lt;/P&gt;</description>
    <pubDate>Wed, 23 Feb 2022 13:45:15 GMT</pubDate>
    <dc:creator>ChristopherPawlyszyn</dc:creator>
    <dc:date>2022-02-23T13:45:15Z</dc:date>
    <item>
      <title>ArcGIS Portal patching order?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-portal-patching-order/m-p/1146705#M32489</link>
      <description>&lt;P&gt;I was having cross scripting(XSS) errors come up on my security scans. I did a quick google search and found there was this patch available:&amp;nbsp;&lt;A href="https://support.esri.com/en/download/7937" target="_blank" rel="noopener"&gt;ArcGIS Server Security 2021 Update 2 Patch (esri.com)&lt;/A&gt;. After installing the patch I re-ran my security scanner and still had&amp;nbsp; XSS errors. Doing more searching reviled that there was an earlier patch: &lt;A href="https://support.esri.com/en/download/7899" target="_blank" rel="noopener"&gt;Portal for ArcGIS Security 2021 Update 1 Patch (esri.com)&lt;/A&gt;&amp;nbsp;. Does any one know if you can apply patches out of order?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 21:32:05 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-portal-patching-order/m-p/1146705#M32489</guid>
      <dc:creator>JustinMaynard</dc:creator>
      <dc:date>2022-02-22T21:32:05Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Portal patching order?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-portal-patching-order/m-p/1146927#M32496</link>
      <description>&lt;P&gt;Security patches for different products are released at different frequencies, so you shouldn't have any problem with installing the Portal for ArcGIS security patch following the installation of the ArcGIS Server security patch.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Feb 2022 13:45:15 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-portal-patching-order/m-p/1146927#M32496</guid>
      <dc:creator>ChristopherPawlyszyn</dc:creator>
      <dc:date>2022-02-23T13:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Portal patching order?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-portal-patching-order/m-p/1148387#M32559</link>
      <description>&lt;P&gt;Hey, can I ask what security scans?&amp;nbsp; I initially thought you meant the portalscan.py or serverscan.py, but the portalscan.py doens't seem to have reference to xss and while serverscan.py does:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Scott_Tansley_0-1645998868407.png" style="width: 400px;"&gt;&lt;img src="https://community.esri.com/t5/image/serverpage/image-id/35083i6F6C8565C790ECFB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Scott_Tansley_0-1645998868407.png" alt="Scott_Tansley_0-1645998868407.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;That's a setting change in the admin API rather than a patch.&amp;nbsp; I know that some people use third party security scanners or have penetration testers, and they may have picked up on this.&amp;nbsp; If that's the case then the issue is likely in your web server, rather than Esri.&amp;nbsp; For example, if you use IIS as a default build and install a Web Adaptor, the Web Adaptor does not harden IIS.&amp;nbsp; You have to invest a fair amount of effort into IIS to tighten security and exclude/modify headers to meet this conditions.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Feb 2022 21:56:27 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-portal-patching-order/m-p/1148387#M32559</guid>
      <dc:creator>Scott_Tansley</dc:creator>
      <dc:date>2022-02-27T21:56:27Z</dc:date>
    </item>
  </channel>
</rss>

