PROBLEM
Log4j 1.2.x vulnerabilities in ArcGIS Pro have been mitigated in the following patches. While the vulnerabilities were mitigated, some security scanners may continue to detect log4j after applying one of these patches. This article outlines why log4j may continue to be detected.
ArcGIS Pro version | Patch that addresses Log4j 1.2.x vulnerabilities* |
---|---|
2.9 | 2.9.2 |
2.8 | 2.8.6 |
2.7 | 2.7.6 |
2.6 | 2.6.9 |
* ArcGIS Pro patches are cumulative, so subsequent patches for each version, for example, 2.7.7. also includes the fix.
Log4j 1.2.x vulnerabilities addressed
The following CVEs have been addressed in the ArcGIS Pro patches:
To learn more about how Esri is addressing all products, see the Log4j vulnerabilities blog. Contact Esri Support for any questions.
Article ID: 000027224
Get help from ArcGIS experts
Download the Esri Support App