<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Audit issues are there in My Application. in ArcGIS Online Questions</title>
    <link>https://community.esri.com/t5/arcgis-online-questions/security-audit-issues-are-there-in-my-application/m-p/1541296#M61626</link>
    <description>&lt;P&gt;Hi, best report your issue here: &lt;A href="https://trust.arcgis.com/en/security-concern/" target="_blank"&gt;Report a Security or Privacy Concern | ArcGIS Trust Center | Documentation&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 23 Sep 2024 13:04:43 GMT</pubDate>
    <dc:creator>SimonSchütte_ct</dc:creator>
    <dc:date>2024-09-23T13:04:43Z</dc:date>
    <item>
      <title>Security Audit issues are there in My Application.</title>
      <link>https://community.esri.com/t5/arcgis-online-questions/security-audit-issues-are-there-in-my-application/m-p/1540834#M61600</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;I used ArcGIS SDK in my application. After auditing of my application they found few security issue.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1. Use of a Broken Risky Cryptographic Algorithm. -&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;com/esri/arcgisruntime/internal/apachehttp/client5/http/impl/auth/k.java&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Description :&lt;/STRONG&gt;&lt;BR /&gt;The use of a broken risky cryptographic algorithm is an unnecessary risk that may result&lt;BR /&gt;in the disclosure of sensitive information. The use of a non-standard algorithm is&lt;BR /&gt;dangerous because a determined attacker may be able to break the&lt;BR /&gt;algorithm compromise whatever data has been protected. Well-known techniques may&lt;BR /&gt;exist to break the algorithm.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Impact :&lt;/STRONG&gt;&lt;BR /&gt;The use of a non-standard algorithm is dangerous because a determined attacker may&lt;BR /&gt;be able to break the algorithm compromise whatever data has been protected. Well-known techniques may exist to break the algorithm.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-09-20 144757.png" style="width: 999px;"&gt;&lt;img src="https://community.esri.com/t5/image/serverpage/image-id/115550i1FBED12FA97D0241/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-09-20 144757.png" alt="Screenshot 2024-09-20 144757.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2.&amp;nbsp;Insecure WebView Implementation. -&amp;gt; com/esri/arcgisruntime/security/DefaultOAuthIntentReceiver.java&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Description :&lt;/STRONG&gt;&lt;BR /&gt;WebView ignores SSL Certificate errors accept any SSL Certificate.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Impact :&lt;/STRONG&gt;&lt;BR /&gt;Insecure WebView Implementation leads to MITM attacks&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-09-20 145117.png" style="width: 999px;"&gt;&lt;img src="https://community.esri.com/t5/image/serverpage/image-id/115551i76569BF0010DED7C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-09-20 145117.png" alt="Screenshot 2024-09-20 145117.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I had below android&amp;nbsp;implementation version.&lt;/P&gt;&lt;PRE&gt;implementation &lt;SPAN&gt;'com.esri.arcgisruntime:arcgis-android:100.15.4'&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;Please check the attached images for your reference.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly suggest me to what are the necessary steps or process to fix this audit issues.&lt;/P&gt;&lt;P&gt;Thank You,&lt;/P&gt;&lt;P&gt;Jyoshna&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2024 09:23:27 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-online-questions/security-audit-issues-are-there-in-my-application/m-p/1540834#M61600</guid>
      <dc:creator>JyoshnaRani</dc:creator>
      <dc:date>2024-09-20T09:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: Security Audit issues are there in My Application.</title>
      <link>https://community.esri.com/t5/arcgis-online-questions/security-audit-issues-are-there-in-my-application/m-p/1541296#M61626</link>
      <description>&lt;P&gt;Hi, best report your issue here: &lt;A href="https://trust.arcgis.com/en/security-concern/" target="_blank"&gt;Report a Security or Privacy Concern | ArcGIS Trust Center | Documentation&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 13:04:43 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-online-questions/security-audit-issues-are-there-in-my-application/m-p/1541296#M61626</guid>
      <dc:creator>SimonSchütte_ct</dc:creator>
      <dc:date>2024-09-23T13:04:43Z</dc:date>
    </item>
  </channel>
</rss>

