laptop and a wrench


The version of Apache Derby that ships with ArcGIS for Server is outdated and has been flagged as being susceptible to an information disclosure vulnerability. Consider updating to Apache Derby or higher.

Last Published: October 27, 2015 ArcGIS for Server
Bug ID Number BUG-000090316
SubmittedAugust 27, 2015
Last ModifiedJuly 28, 2020
Applies toArcGIS for Server
Version found10.3.1
Operating SystemWindows
Operating System Version2012 64 Bit
StatusWill Not Be Addressed

Additional Information

This is a vulnerability in Apache Derby. It does not impact and cannot be used to exploit ArcGIS for Server.

Steps to Reproduce

Bug ID: BUG-000090316


  • ArcGIS for Server

Get help from ArcGIS experts

Contact technical support

Download the Esri Support App

Go to download options

Discover more on this topic