laptop and a wrench

Bug

Reflected cross-site scripting (XSS) vulnerability in ArcGIS Server.

ArcGIS GIS Server
Bug ID Number BUG-000175692
SubmittedApril 9, 2025
Last ModifiedSeptember 8, 2025
Applies toArcGIS GIS Server
Version found11.4
Operating SystemN/A
Operating System VersionN/A
StatusIn Product Plan

Workaround

Disable the services directory per best practices.

Steps to Reproduce

Bug ID: BUG-000175692

Software:

  • ArcGIS GIS Server

Get notified when the status of a bug changes

Download the Esri Support App

Discover more on this topic

Get help from ArcGIS experts

Contact technical support

Download the Esri Support App

Go to download options