<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ArcGIS Enterprise Security Patch Dec 2023 in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1361552#M38011</link>
    <description>&lt;P&gt;Per&amp;nbsp;&lt;A href="https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/portal-for-arcgis-enterprise-sites-security-patch-is-now-available/" target="_blank" rel="noopener"&gt;Portal for ArcGIS Enterprise Sites 2023 Security Patch (esri.com)&lt;/A&gt;, "Customers working with versions prior to ArcGIS 11.1 who cannot patch at this time may mitigate all security issues addressed by the Portal for ArcGIS Enterprise Sites Security Patch.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Mitigation Options include:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Option 1: Upgrade your deployment to ArcGIS Enterprise 11.2&amp;nbsp;to completely remediate these vulnerabilities.&lt;/P&gt;&lt;P&gt;Option 2: Remove members from ArcGIS Enterprise Sites&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://enterprise.arcgis.com/en/sites/latest/team/how-teams-work.htm" target="_blank" rel="noopener"&gt;Core Team groups&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;In either case, ArcGIS Enterprise sites will remain accessible."&lt;/P&gt;&lt;P&gt;Please correct me if I'm interpreting this statement incorrectly.&amp;nbsp; I'm using ArcGIS Enterprise 10.9.1 and have applied the patch back in June.&amp;nbsp; Mitigation is one of the options listed above, meaning that I can upgrade to 11.2 to resolve the issue?&amp;nbsp; I'm scheduled to upgrade our Dev Environment after the Christmas.&amp;nbsp; Was planning to do 11.1 but with this issue will be upgrading to 11.2.&amp;nbsp; Thank you!&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 15 Dec 2023 18:36:29 GMT</pubDate>
    <dc:creator>Pei-SanTsai</dc:creator>
    <dc:date>2023-12-15T18:36:29Z</dc:date>
    <item>
      <title>ArcGIS Enterprise Security Patch Dec 2023</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1360892#M37983</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;On the Dec 8 2023 Enterprise Security patch notice (&amp;nbsp;&lt;A href="https://support.esri.com/en-us/patches-updates/2023/defective-arcgis-enterprise-patch" target="_self"&gt;https://support.esri.com/en-us/patches-updates/2023/defective-arcgis-enterprise-patch&lt;/A&gt;&amp;nbsp; ) there is very little actual detail beyond 'please wait for us/do nothing to get a fix in place' What is the actual problem so we can monitor for aberrant activity?&lt;/P&gt;&lt;P&gt;Is there a CVE generated for this event that provides additional details so I can log it with my IT department?&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2023 15:07:50 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1360892#M37983</guid>
      <dc:creator>ThomasHoman</dc:creator>
      <dc:date>2023-12-14T15:07:50Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Security Patch Dec 2023</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1360938#M37986</link>
      <description>&lt;P&gt;I just received notice of this yesterday and have this defective patch installed. Per the email that was sent out, it said the patch defect can have "serious consequences", yet doesn't specify what the "serious consequences" are. As the server administrator, I need to know what these consequences are so I can monitor for aberrant behavior like the original poster mentioned.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit: I realize that even if we knew what the consequences are, we might not be able to do much about it until Esri releases the fix. But at least I'd be able to immediately pinpoint the problem instead of spending hours trying to find it myself, reaching out to support, etc. We have hundreds of users that depend on Portal being up and running so it is vital that we are kept aware of these sorts of things and know what kind of behavior to expect from defective patches.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2023 16:32:08 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1360938#M37986</guid>
      <dc:creator>RyanUthoff</dc:creator>
      <dc:date>2023-12-14T16:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Security Patch Dec 2023</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1360999#M37990</link>
      <description>&lt;P&gt;Hi James, Hi Ryan,&lt;/P&gt;&lt;P&gt;The ArcGIS Enterprise 11.1 version of this patch AND the required&amp;nbsp;ArcGIS Validation and Repair tool are available.&amp;nbsp;We describe the defect the original&amp;nbsp;&lt;SPAN&gt;Portal for ArcGIS Enterprise Sites Security Patch introduced and also provide the download location here:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://support.esri.com/en-us/patches-updates/2023/defective-arcgis-enterprise-patch" target="_blank"&gt;https://support.esri.com/en-us/patches-updates/2023/defective-arcgis-enterprise-patch&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;We recently updated our Portal for ArcGIS Validation and Repair tool page here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.esri.com/en-us/patches-updates/2023/portal-for-arcgis-validation-and-repair" target="_blank"&gt;https://support.esri.com/en-us/patches-updates/2023/portal-for-arcgis-validation-and-repair&lt;/A&gt;&lt;/P&gt;&lt;P&gt;We also recently updated our security advisory , which found under the Advisories section of the &lt;A href="https://trust.arcgis.com" target="_self"&gt;ArcGIS Trust Center.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The specific CVEs addressed in the are documented in the advisory.&lt;/P&gt;&lt;P&gt;Linux users are unaffected by the issues introduced by the flawed patch.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Users who have not yet installed the&amp;nbsp;&lt;SPAN&gt;Portal for ArcGIS Enterprise Sites Security Patch can immediately remediate the security issues that this patch resolves with an upgrade to 11.2.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;All of the issues that the Portal for ArcGIS Enterprise Sites Security Patch addresses require the ability for a malicious user to manage an ArcGIS Enterprise Site. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mitigation options include temporarily revoking user memberships from the &lt;A href="https://enterprise.arcgis.com/en/sites/latest/team/configure-roles-and-privileges.htm#ESRI_SECTION1_1719C2750D4B404A846B72EA683151C2" target="_self"&gt;Sites Core Group&lt;/A&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2023 17:53:44 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1360999#M37990</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2023-12-14T17:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Security Patch Dec 2023</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1361001#M37991</link>
      <description>&lt;P&gt;I think the information you are looking for is on this page:&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.esri.com/en-us/patches-updates/2023/portal-for-arcgis-enterprise-sites-security-patch" target="_blank"&gt;https://support.esri.com/en-us/patches-updates/2023/portal-for-arcgis-enterprise-sites-security-patch&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I agree the description is not the clearest, but if I interpret this well, the main point seems to be the potential failure of a high availability "standby machine", as described in the quote visible below, which could of course be pretty problematic if your main server goes down due to a problem. Note that this issue only affects Windows installs according to the text:&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;BUG-000160830 - Installing the 11.1 version of the Portal for ArcGIS Enterprise Sites Security Patch results in failures on the standby machine in highly available environments. (11.1 only)&lt;/BLOCKQUOTE&gt;&lt;P&gt;I think the other bug numbers mentioned in the quote below, are actually the exact same issue, just with a different bug number for each version of ArcGIS Enterprise:&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;The defects that motivated the temporary disablement of the patches are BUG-000163367 (version 11.1), BUG-000160895 (version 10.9.1), and BUG-000161711 (version 10.8.1) and only impact Windows.&lt;BR /&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2023 17:55:04 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1361001#M37991</guid>
      <dc:creator>MarcoBoeringa</dc:creator>
      <dc:date>2023-12-14T17:55:04Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Security Patch Dec 2023</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1361019#M37992</link>
      <description>&lt;P&gt;Thank you for the link to the ArcGIS Trust Center. That gives me the information I was looking for. The technical support articles I've seen haven't included that link, so I wasn't aware it existed. And bug fixes in the corrected patch give the impression that the bug only exists in 11.1,&amp;nbsp;even though the&amp;nbsp;&lt;SPAN&gt;Portal for ArcGIS Validation and Repair tool is available for 10.8.1, 10.9.1, and 11.1. So overall, it's a little confusing to figure out what's going on but I appreciate your response.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2023 18:13:56 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1361019#M37992</guid>
      <dc:creator>RyanUthoff</dc:creator>
      <dc:date>2023-12-14T18:13:56Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Security Patch Dec 2023</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1361052#M37993</link>
      <description>&lt;P&gt;Hello Ryan,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;I can confirm that we have three separate issues so that we can track impact across different versions of ArcGIS Enterprise. We will be re-deploying the patch along with additional tooling for each affected version of ArcGIS Enterprise. More information to come!&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2023 19:03:15 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1361052#M37993</guid>
      <dc:creator>JonEmch</dc:creator>
      <dc:date>2023-12-14T19:03:15Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Security Patch Dec 2023</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1361163#M37998</link>
      <description>&lt;P&gt;To be clear, there are a few issues in play:&lt;/P&gt;&lt;OL class="lia-list-style-type-lower-alpha"&gt;&lt;LI&gt;We released a series of patches for ArcGIS Enterprise Sites to address a few cross site scripting issues.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;While the patches fixed those issues, on Windows hosts, it introduced an issue that could result in system availability challenges if additional patches or upgrades were subsequently installed.&amp;nbsp;&lt;UL&gt;&lt;LI&gt;This is what prompted us to pull that patch, and it took some time to develop a fix. This is an unprecedented issue for us, and required a major engineering effort to us to release the tool that fixes this problem.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;At the same time, we needed to produce a new&amp;nbsp;patch for ArcGIS Enterprise Sites that wouldn't introduce this issue.&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2023 21:23:06 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1361163#M37998</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2023-12-14T21:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Security Patch Dec 2023</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1361181#M38002</link>
      <description>&lt;P&gt;Regarding CVEs in general - when we release a security patch, we release an advisory that's discoverable on the ArcGIS Trust Center.&amp;nbsp;&lt;/P&gt;&lt;P&gt;An easy way to review all of the CVEs we've released:&lt;/P&gt;&lt;P&gt;&lt;A href="https://nvd.nist.gov/vuln/search/results?form_type=Advanced&amp;amp;results_type=overview&amp;amp;search_type=all&amp;amp;isCpeNameSearch=false&amp;amp;cpe_vendor=cpe%3A%2F%3Aesri" target="_blank"&gt;https://nvd.nist.gov/vuln/search/results?form_type=Advanced&amp;amp;results_type=overview&amp;amp;search_type=all&amp;amp;isCpeNameSearch=false&amp;amp;cpe_vendor=cpe%3A%2F%3Aesri&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2023 21:54:55 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1361181#M38002</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2023-12-14T21:54:55Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Security Patch Dec 2023</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1361272#M38005</link>
      <description>&lt;P&gt;Agreed. I had never heard of the trust portal as well.&lt;/P&gt;&lt;P&gt;Thanks you very much for the additional information.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2023 02:24:34 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1361272#M38005</guid>
      <dc:creator>ThomasHoman</dc:creator>
      <dc:date>2023-12-15T02:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Security Patch Dec 2023</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1361552#M38011</link>
      <description>&lt;P&gt;Per&amp;nbsp;&lt;A href="https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/portal-for-arcgis-enterprise-sites-security-patch-is-now-available/" target="_blank" rel="noopener"&gt;Portal for ArcGIS Enterprise Sites 2023 Security Patch (esri.com)&lt;/A&gt;, "Customers working with versions prior to ArcGIS 11.1 who cannot patch at this time may mitigate all security issues addressed by the Portal for ArcGIS Enterprise Sites Security Patch.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Mitigation Options include:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Option 1: Upgrade your deployment to ArcGIS Enterprise 11.2&amp;nbsp;to completely remediate these vulnerabilities.&lt;/P&gt;&lt;P&gt;Option 2: Remove members from ArcGIS Enterprise Sites&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://enterprise.arcgis.com/en/sites/latest/team/how-teams-work.htm" target="_blank" rel="noopener"&gt;Core Team groups&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;In either case, ArcGIS Enterprise sites will remain accessible."&lt;/P&gt;&lt;P&gt;Please correct me if I'm interpreting this statement incorrectly.&amp;nbsp; I'm using ArcGIS Enterprise 10.9.1 and have applied the patch back in June.&amp;nbsp; Mitigation is one of the options listed above, meaning that I can upgrade to 11.2 to resolve the issue?&amp;nbsp; I'm scheduled to upgrade our Dev Environment after the Christmas.&amp;nbsp; Was planning to do 11.1 but with this issue will be upgrading to 11.2.&amp;nbsp; Thank you!&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2023 18:36:29 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1361552#M38011</guid>
      <dc:creator>Pei-SanTsai</dc:creator>
      <dc:date>2023-12-15T18:36:29Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Security Patch Dec 2023</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1361553#M38012</link>
      <description>&lt;P&gt;&lt;U&gt;&lt;EM&gt;&lt;STRONG&gt;NO. DO NOT ATTEMPT TO UPGRADE OR INSTALL ANY PATCHES UNTIL THE 10.9.1&amp;nbsp;Validation and Repair tool&amp;nbsp;IS AVAILABLE.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Upgrading is an option to remediate the Sites vulnerabilities IF and ONLY IF this faulty patch has not yet been installed.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2023 18:41:56 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1361553#M38012</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2023-12-15T18:41:56Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Security Patch Dec 2023</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1362884#M38055</link>
      <description>&lt;P&gt;Hello folks,&lt;/P&gt;&lt;P&gt;We've made some substantial additions to our knowledge article on this issue:&amp;nbsp;&lt;A href="https://support.esri.com/en-us/patches-updates/2023/defective-arcgis-enterprise-patch" target="_self"&gt;Defective Portal for ArcGIS Enterprise Sites Security Patch.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Please let me know if there are any questions, we are here to help.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 23:06:35 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1362884#M38055</guid>
      <dc:creator>JonEmch</dc:creator>
      <dc:date>2023-12-19T23:06:35Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Security Patch Dec 2023</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1362932#M38059</link>
      <description>&lt;P&gt;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/144649"&gt;@JonEmch&lt;/a&gt;&amp;nbsp;Is WebGISDR affected by this defective patch? Hypothetically, let's say we have an ArcGIS Enterprise deployment with the defective patch installed. If for some reason, we needed to do a WebGISDR restore to a brand new environment with a fresh installation of ArcGIS Enterprise (without the defective patch installed), would we expect to see any problems with that?&lt;/P&gt;&lt;P&gt;Also, thank you for adding the additional information to the knowledge article! It is very detailed and thorough which I appreciate!&lt;/P&gt;&lt;P&gt;Edit: I realize that doing a WebGISDR restore to workaround this issue isn't ideal and my not be "recommended." I'm asking because we were already considering moving our Enterprise deployment to new machines, before this defective patch was made public.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 14:24:11 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1362932#M38059</guid>
      <dc:creator>RyanUthoff</dc:creator>
      <dc:date>2023-12-20T14:24:11Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Security Patch Dec 2023</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1363063#M38063</link>
      <description>&lt;P&gt;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/154737"&gt;@RyanUthoff&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WebGISDR is not affected by this patch. This is a possible method of recovery however, I will caution you to wait until the new version of the Portal for ArcGIS Enterprise Sites Security patch is made available for your version of ArcGIS Enterprise before proceeding.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 15:46:59 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1363063#M38063</guid>
      <dc:creator>JonEmch</dc:creator>
      <dc:date>2023-12-20T15:46:59Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Security Patch Dec 2023</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1364449#M38104</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I installed the Portal for ArcGIS Enterprise Sites 2023 Security &lt;A href="https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/portal-for-arcgis-enterprise-sites-security-patch-is-now-available/" target="_self"&gt;Patch package&lt;/A&gt; on the ArcGIS Enterprise 11.1 Portal server. I followed the &lt;A href="https://support.esri.com/en-us/patches-updates/2023/defective-arcgis-enterprise-patch" target="_self"&gt;instructions&lt;/A&gt; exactly and first ran The Portal for ArcGIS &lt;A href="https://support.esri.com/en-us/patches-updates/2023/portal-for-arcgis-validation-and-repair" target="_self"&gt;Validation and Repair&lt;/A&gt; program, which fixed the faulty program.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-12-27 101218.png" style="width: 582px;"&gt;&lt;img src="https://community.esri.com/t5/image/serverpage/image-id/90000i1005D4CA9FCFE46D/image-size/large?v=v2&amp;amp;px=999" role="button" title="2023-12-27 101218.png" alt="2023-12-27 101218.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;After that, I installed all the available software fixes.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ArcGIS Portal 2023-12-26 094637.png" style="width: 999px;"&gt;&lt;img src="https://community.esri.com/t5/image/serverpage/image-id/90001iE0D38521DE2ACB96/image-size/large?v=v2&amp;amp;px=999" role="button" title="ArcGIS Portal 2023-12-26 094637.png" alt="ArcGIS Portal 2023-12-26 094637.png" /&gt;&lt;/span&gt;&lt;BR /&gt;Finally, I ran the PatchFinder.exe Utility program to make sure that version C was installed on the machine.&amp;nbsp;At this point, it is important to restart the Portal server.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-12-27 095634.png" style="width: 548px;"&gt;&lt;img src="https://community.esri.com/t5/image/serverpage/image-id/90002i5120FE54E621F7DD/image-size/large?v=v2&amp;amp;px=999" role="button" title="2023-12-27 095634.png" alt="2023-12-27 095634.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;After that, I carefully tested in the ArcGIS Enterprise environment that everything works as it should in the Portal's browser applications, Field Maps, and ArcGIS Pro.&amp;nbsp;Everything seems to work perfectly. It is good to reserve 3-4 hours of working time for software patch installations per server.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2023 09:19:44 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1364449#M38104</guid>
      <dc:creator>JuhaHaanpera</dc:creator>
      <dc:date>2023-12-27T09:19:44Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Security Patch Dec 2023</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1370565#M38246</link>
      <description>&lt;P&gt;Another question related to WebGISDR. Is changing the Portal Database password in the Portal Admin endpoint going to cause any issues related to this bug? We're testing the WebGISDR but don't know the password to the DB which we need for creating the initial Portal admin account in the new environment in order for the restore to work.&lt;/P&gt;&lt;P&gt;Of course we won't do the restore "for real" until after the fix is released. But I can't test the restore without changing the password first. If there is any risk associated with changing the Portal DB password, we'll wait. Otherwise, we'd like to go ahead and do some testing while we wait for the fix to be released. I'm just being overly cautious since I don't want to "trigger" the bug.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 17:03:40 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-security-patch-dec-2023/m-p/1370565#M38246</guid>
      <dc:creator>RyanUthoff</dc:creator>
      <dc:date>2024-01-16T17:03:40Z</dc:date>
    </item>
  </channel>
</rss>

