|
BLOG
|
There is an updated version in the customer exclusive documents repository in the ArcGIS Trust Center. https://trust.arcgis.com/en/customer-documents/
... View more
11-20-2023
06:03 AM
|
3
|
0
|
7682
|
|
POST
|
Esri's current statement regarding LibWebP is: Esri utilizes the LibWebP library in a number of products, however they have not been demonstrated as exploitable at this time. Out of an abundance of caution, all products utilizing the LibWebP component will be updated as part of the next product release. Patches for older versions will be considered for products where there is additional risk identified.
... View more
10-17-2023
08:39 AM
|
4
|
0
|
2211
|
|
POST
|
Esri is aware of CVE-2023-4863, which has recently seen broad media attention due to the impact to the commonly leveraged image library libwebp. We are also tracking CVE-2023-5217, which has not attracted as much media attention. The libwebp library is used to process images created in the webp image format. CVE-2023-4863 is known to have been exploited in the wild by an attacker tricking a victim into opening an HTML page that contains a specifically crafted webp image, triggering a buffer overflow. CVE-2023-5217 is a similar issue, found in libvpx. The libpvx library is used to process videos created with the VPX codec. CVE-2023-5217 is also known to have been exploited in the wild. We are investigating the impact of these vulnerabilities in these 3rd party components in our software. We encourage you to subscribe to the RSS feed on the ArcGIS Trust Center for the latest as it becomes available.
... View more
10-02-2023
01:43 PM
|
8
|
0
|
2888
|
|
POST
|
Web server logs will be the best way to collect this information.
... View more
08-30-2023
06:05 AM
|
0
|
1
|
2615
|
|
BLOG
|
OOPS, I'm forever tranposing the vuln scan guidnce and the AV guidance and the link is indeed broken. I'll work with our doc team to get this fixed.
... View more
08-28-2023
11:00 AM
|
1
|
0
|
8305
|
|
POST
|
Agree on the "too many layers" point. those should be split into different services with themes. Nobody's going to view all 100 of those layers at a time. I believe that this may be the answer to your question though: https://enterprise.arcgis.com/en/server/10.6/publish-services/windows/map-authoring-considerations.htm#ESRI_SECTION1_4C54586DEB0445B4B97AF15856E546AB
... View more
08-28-2023
08:04 AM
|
1
|
0
|
1638
|
|
POST
|
Looks like your front end web server may only support HTTP/2, where Workflow Manager likely requires HTTP/1.1. - or potentially vice-versa. Because the front end is sending in a format than the back-end server expects, an error is thrown.
... View more
08-28-2023
08:01 AM
|
0
|
1
|
2771
|
|
BLOG
|
Link changed w/ version 3.1: https://trust.arcgis.com/en/customer-documents/ArcGIS_Vulnerability_Scanning_Guidance_v31.pdf Check out the other resources in the customer exclusive area of the ArcGIS Trust Center. You may also find the WAF guide helpful.
... View more
08-28-2023
07:50 AM
|
0
|
0
|
8332
|
|
BLOG
|
@CarlosBarahona Yes. We recently implemented the webAuthN API and are working on the design to allow admins to require MFA for built-in accounts. WebAuthN was a prerequisite. This feature should be implemented in the near future.
... View more
08-07-2023
08:07 AM
|
1
|
0
|
2417
|
|
POST
|
In a future release, we'll be offering a headless token approach that should ease some of this challenge. That will allow for mandatory MFA for user accounts along with the ability to use "service accounts". ArcGIS Enterprise now supports gMSA out of the box.
... View more
08-07-2023
06:54 AM
|
2
|
0
|
1683
|
|
POST
|
Sorry about that, I could have sworn they were archives, not binary files. You can explode the cache using desktop or a tool like https://mapproxy.org/docs/1.13.0/mapproxy_util.html#export
... View more
07-28-2023
10:38 AM
|
0
|
0
|
1185
|
|
POST
|
It's possible, but you shouldn't have to and I'd recommend against it. A .bundle file is just a gzipped collection of files and folders, and modern AV scanners should be able to see inside of it without unpacking it. 7zip should be able to open a cache bundle, but depending on how many tiles and LODs there are, it could take a very very long time to extract them all and may consume a lot of space on disk.
... View more
07-26-2023
07:15 AM
|
1
|
1
|
1201
|
|
POST
|
If your IA team needs an artifact, they can look this up in our 3rd party CVE response tool. It's in the customer exclusive documents are in the ArcGIS Trust Center.
... View more
07-07-2023
08:27 AM
|
2
|
1
|
3282
|
|
POST
|
Jackson deserialization issues are not exploitable in the Enterprise base enterprise deployment. In general, if you're not using a given service like Geoevent, you should disable the Geoevent service or uninstall it so that you limit the potential attack surface - but the Jackson-Databind dependency is in ArcGIS Server as well. It'd brought in as a dependency upon dependency of other 3rd party frameworks.
... View more
07-07-2023
08:26 AM
|
1
|
0
|
3282
|
|
POST
|
No, this functionality does not exist. You need access to the web server root.
... View more
05-19-2023
10:25 AM
|
1
|
0
|
1591
|
| Title | Kudos | Posted |
|---|---|---|
| 3 | 3 weeks ago | |
| 1 | 05-24-2018 07:28 AM | |
| 2 | 05-12-2025 07:33 AM | |
| 1 | 04-29-2025 10:45 AM | |
| 1 | 03-20-2025 08:11 AM |
| Online Status |
Online
|
| Date Last Visited |
28m ago
|