ArcGIS for Server Security (January 2015) Patch

Summary

This security patch addresses vulnerabilities found in ArcGIS for Server. Esri recommends that all customers using ArcGIS Server 10.1 SP1 QIP and 10.2 apply this patch. Customers who are using 10.2 should first apply 10.2.1 or 10.2.2.

Description

Introduction


Esri® announces the ArcGIS for Server Security (January 2015) Patch. Esri recommends that all customers using ArcGIS for Server 10.1 SP1 QIP, 10.2.1, and 10.2.2 apply this patch. This patch deals specifically with the issues listed under Issues Addressed with this patch.


Esri strongly recommends the installation of the latest security patches on all products. If you are using the ArcGIS Web Adaptor for Java, you must also install the ArcGIS Web Adaptor for Java (January 2015) Security Patch.


This security patch is cumulative and includes several non-security related fixes from an earlier patch, the ArcGIS 10.2.2 for (Desktop, Engine, Server) Geodatabase and Feature Service Sync Optimization Patch. Some of the geodatabase fixes from that earlier patch (NIM08625, NIM099098, NIM100503, NIM091900, NIM094929, NIM088921, NIM098196, NIM100823, NIM101030, and NIM101204) require a geodatabase upgrade to take effect. A geodatabase upgrade is not required for the security fixes to be effective and no new problems will occur if the geodatabase is not upgraded.


Installing this patch on Windows


Installation Steps:


ArcGIS 10.1 SP1 QIP, 10.2.1, or 10.2.2 for Server must be installed before installing this patch.

  1. Download the appropriate file to a location other than your ArcGIS installation location.

  2.     Checksum (Md5)
    ArcGIS 10.1 SP1 QIP for Server ArcGIS-101SP1QIP-S-SEC-JAN2015-Patch.msp 110DE2A0F44A93036F224F5DFFE640D4
         
    ArcGIS 10.2.1 for Server ArcGIS-1021-S-SEC-JAN2015-Patch.msp

    07BADADBBCD98D13916F81E035E94D6B

         
    ArcGIS 10.2.2 for Server ArcGIS-1022-S-SEC-JAN2015-Patch.msp 4E1D47EA5A9E6B9F27DC1374588FB91F

  3. Make sure you have write access to your ArcGIS installation location.

  4. Double-click ArcGIS-<Version>-S-SEC-JAN2015-Patch.msp to start the setup process.

    NOTE: If double clicking on the MSP file does not start the setup installation, you can start the setup installation manually by using the following command:

    msiexec.exe /p [location of Patch]\ArcGIS-<Version>-S-SEC-JAN2015-Patch.msp

Installing this patch on Linux


Installation Steps:


Complete the following install steps as the ArcGIS Install owner. The Install owner is the owner of the arcgis folder.

ArcGIS 10.1 SP1 QIP, 10.2.1, or 10.2.2 for Server must be installed before installing this patch.

  1. Download the appropriate file to a location other than your ArcGIS installation location.


        Checksum (Md5)
    ArcGIS 10.1 SP1 QIP for Server ArcGIS-101SP1QIP-S-SEC-JAN2015-Patch-lx.tar 5CF0C911B724D2C0C26A8E2F24F756FD
         
    ArcGIS 10.2.1 for Server ArcGIS-1021-S-SEC-JAN2015-Patch-lx.tar 99C583EFEAB77235B5EE4AB03DD9D591
         
    ArcGIS 10.2.2 for Server ArcGIS-1022-S-SEC-JAN2015-Patch-lx.tar 88E41239EEE837216C8B9F4A6BCD939A

  2. Make sure you have write access to your ArcGIS installation location, and that no one is using ArcGIS.

  3. Extract the specified tar file by typing:

    % tar -xvf ArcGIS-<Version>-S-SEC-JAN2015-Patch-lx.tar

  4. Start the installation by typing:

    % ./applypatch

    This will start the dialog for the menu-driven installation procedure. Default selections are noted in parentheses ( ). To quit the installation procedure, type 'q' at any time.

Uninstalling this patch

To uninstall this patch on Windows, open the Windows Control Panel and navigate to installed programs. Make sure that "View installed updates" (upper left side of the Programs and Features dialog) is active. Select the ArcGIS for Server Security (January 2015) Patch from the programs list and click Uninstall to remove the patch.

To uninstall this patch on Linux, you will need to completely uninstall the ArcGIS for Server product. For more information regarding uninstalling ArcGIS for Server please see the Uninstalling ArcGIS for Server on Linux page.

Patch Updates

Check the Patches and Service Packs page periodically for the availability of additional patches. New information about this patch will be posted here.

February 9, 2015: The ArcGIS 10.1 SP1 QIP version is now released.

February 18, 2015: The ArcGIS 10.2.2 version is now released.

How to identify which ArcGIS products are installed

To determine which ArcGIS products are installed, choose the appropriate version of the PatchFinder utility for your environment and run it from your local machine. PatchFinder will list all products, hot fixes, and patches installed on your local machine.

Getting Help

Domestic sites, please contact Esri Technical Support at 1-888-377-4575, if you have any difficulty installing this patch. International sites, please contact your local Esri software distributor.