PROBLEM
Log4j 1.2.x vulnerabilities in ArcGIS Pro have been mitigated in the following patches. While the vulnerabilities were mitigated, some security scanners may continue to detect log4j after applying one of these patches. This article outlines why log4j may continue to be detected.
| ArcGIS Pro version | Patch that addresses Log4j 1.2.x vulnerabilities* |
|---|---|
| 2.9 | 2.9.2 |
| 2.8 | 2.8.6 |
| 2.7 | 2.7.6 |
| 2.6 | 2.6.9 |
* ArcGIS Pro patches are cumulative, so subsequent patches for each version, for example, 2.7.7. also includes the fix.
Log4j 1.2.x vulnerabilities addressed
The following CVEs have been addressed in the ArcGIS Pro patches:
To learn more about how Esri is addressing all products, see the Log4j vulnerabilities blog. Contact Esri Support for any questions.
Artikel-ID: 000027224
Unterstützung durch ArcGIS-Experten anfordern
Beginnen Sie jetzt mit dem Chatten