English

ArcGIS Server Security 2017 Update 1 Patch

Summary

This security patch addresses multiple security vulnerabilities found in ArcGIS for Server. Esri recommends that all customers using ArcGIS Server 10.4.1 and 10.4 apply this patch. This security patch is cumulative and includes several non-security related fixes.

Description

Introduction

Esri® announces the ArcGIS Server Security 2017 Update 1 Patch. Esri recommends that all customers using ArcGIS Server 10.4.1 and 10.4 apply this patch. This patch deals specifically with the issue listed below under Issues Addressed with this patch.

This security patch is cumulative and includes several non-security related fixes from an earlier patch that are also listed below under Issues Addressed with this Patch.

Issues Addressed with this patch


  • BUG-000098119 - ArcGIS Server exposes internal information.

To avoid conflicts the ArcGIS Server 10.4.1 version also includes:
  • BUG-000099629 - Unable to upload files in ArcGIS Server Manager after updating the browser to Firefox 49 or Chrome 54.
  • BUG-000095194 - Feature service REST response periodically does not return full editing capabilities.
  • BUG-000094193 - When a server object interceptor (SOI) is enabled on an ArcGIS Server feature service with the Sync capability, the Create Replica operation fails, which renders the feature service unusable for offline editing.
  • BUG-000093500 - After login, user is redirected to the Services Directory home page instead of URL from which login was attempted.

To avoid conflicts the ArcGIS Server 10.4 version also includes:
  • BUG-000095679 - After creating an ArcGIS Server site with more than 250 service instances, a subsequent restart of ArcGIS Server windows service takes much longer than expected for all the service instances to come up correctly, which makes it difficult to gauge when the services are ready for consumption.

Installing this patch on Windows


Installation Steps:


ArcGIS Server 10.4.1 or 10.4 must be installed before installing this patch.

  1. Download the appropriate file to a location other than your ArcGIS installation location.

  2. ArcGIS 10.4.1   Checksum (Md5)
         
         ArcGIS Server ArcGIS-1041-S-SEC2017U1-Patch.msp A4457BE1F96BA716093D701D25559E29
         
    ArcGIS 10.4   Checksum (Md5)
         
         ArcGIS Server ArcGIS-104-S-SEC2017U1-Patch.msp 7BF54C238B173A77E2B092C85FB62478
         

  3. Make sure you have write access to your ArcGIS installation location.

  4. Double-click ArcGIS-<Version>-S-SEC2017U1-Patch.msp to start the setup process.

    NOTE: If double clicking on the MSP file does not start the setup installation, you can start the setup installation manually by using the following command:

    msiexec.exe /p [location of Patch]\ArcGIS-<Version>-S-SEC2017U1-Patch.msp


Installing this patch on Linux


Installation Steps:


Complete the following install steps as the ArcGIS Install owner. The Install owner is the owner of the arcgis folder.

ArcGIS Server 10.4.1 or 10.4 must be installed before installing this patch.

  1. Download the appropriate file to a location other than your ArcGIS installation location.


    ArcGIS 10.4.1   Checksum (Md5)
         
         ArcGIS Server ArcGIS-1041-S-SEC2017U1-Patch-linux.tar 0F851A9E813D554E9D31C7EE54626671
         
    ArcGIS 10.4   Checksum (Md5)
         
         ArcGIS Server ArcGIS-104-S-SEC2017U1-Patch-linux.tar 2881B75482970D9F0E41B1D4DA2857E7
         

  2. Make sure you have write access to your ArcGIS installation location, and that no one is using ArcGIS.

  3. Extract the specified tar file by typing:

    % tar -xvf ArcGIS-<Version>-S-SEC2017U1-Patch-lx.tar

  4. Start the installation by typing:

    % ./applypatch

    This will start the dialog for the menu-driven installation procedure. Default selections are noted in parentheses ( ). To quit the installation procedure, type 'q' at any time.

Patch Updates

Check the Patches and Service Packs page periodically for the availability of additional patches. New information about this patch will be posted here.

January 19, 2017: ArcGIS 10.4.1 download is now available.

How to identify which ArcGIS products are installed

To determine which ArcGIS products are installed, choose the appropriate version of the PatchFinder utility for your environment and run it from your local machine. PatchFinder will list all products, hot fixes, and patches installed on your local machine.

Getting Help

Domestic sites, please contact Esri Technical Support at 1-888-377-4575, if you have any difficulty installing this patch. International sites, please contact your local Esri software distributor.