Patches and updates
Portal for ArcGIS Operations Dashboard Security Patch
Summary
Description
EsriĀ® announces the Portal for ArcGIS Operations Dashboard Security Patch. This patch addresses a cross-site scripting security issue in Operations Dashboard on ArcGIS Enterprise. The patch is recommended for all users of Operations Dashboard. This patch deals specifically with the issue listed below under Issues Addressed with this patch.
June 16, 2021: This patch has been re-released with a "B" version to address this issue:
Issues Addressed with this patch
- BUG-000123698 - Stored cross-site scripting (XSS) issue in Operations Dashboard.
CVSS 3.0 Base Score: 8.0 - CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Installing this patch on Windows
Installation Steps:
This patch should be installed on all Portal for ArcGIS installations related to the Portal for ArcGIS site.
The ArcGIS product listed in the table must be installed on your system before you can install a patch. Each patch setup is specific to the ArcGIS product in the list. To determine which products are installed on your system, please see the How to identify which ArcGIS products are installed section. Esri recommends that you install the patch for each product that is on your system.
- Download the appropriate file to a location other than your ArcGIS installation location.
ArcGIS 10.7.1 Portal for ArcGIS ArcGIS-1071-PFA-ODS-PatchB.msp Checksum
(SHA256)5EBB3181E35F3FFD1A4867686967C2FADCA35A567183D8885B9486AC22AB7D13
ArcGIS 10.6.1 Portal for ArcGIS ArcGIS-1061-PFA-ODS-PatchB.msp Checksum
(SHA256)406969381BA70A014517D749D4BC2AFA67DE07B4ED7ECBD6A2B814897A943598
- Make sure you have write access to your ArcGIS installation location.
- Double-click ArcGIS-1071-PFA-ODS-Patch.msp to start the setup process.
NOTE: If double clicking on the MSP file does not start the setup installation, you can start the setup installation manually by using the following command:
msiexec.exe /p [location of Patch]\ArcGIS-1071-PFA-ODS-Patch.msp
Installing this patch on Linux
Installation Steps:
Complete the following install steps as the ArcGIS Install owner. The Install owner is the owner of the arcgis folder. This patch should be installed on all Portal for ArcGIS installations related to the Portal for ArcGIS site.
The ArcGIS product listed in the table must be installed on your system before you can install a patch. Each patch setup is specific to the ArcGIS product in the list. To determine which products are installed on your system, please see the How to identify which ArcGIS products are installed section. Esri recommends that you install the patch for each product that is on your system.
- Download the appropriate file to a location other than your ArcGIS installation location.
ArcGIS 10.7.1 Portal for ArcGIS ArcGIS-1071-PFA-ODS-PatchB-linux.tar Checksum
(SHA256)7F9520BFE4BFFE1DEAA06F53FB5E27546A518224CB962A02575BB58E9C948FD3
ArcGIS 10.6.1 Portal for ArcGIS ArcGIS-1061-PFA-ODS-PatchB-linux.tar Checksum
(SHA256)69F03FE0686D54A99FE16C4C19A1D0D9B796AD24FC5BB0A8741897084342AAD7
- Make sure you have write access to your ArcGIS installation location, and that no one is using ArcGIS.
- Extract the specified tar file by typing:
% tar -xvf ArcGIS-1071-PFA-ODS-Patch-linux.tar
- Start the installation by typing:
% ./applypatch
This will start the dialog for the menu-driven installation procedure. Default selections are noted in parentheses ( ). To quit the installation procedure, type 'q' at any time.
Uninstalling this patch on Windows
Uninstalling this patch on Linux
./removepatch.sh
The removepatch.sh script allows you to uninstall previously installed patches or hot fixes. Use the -s status flag to get the list of installed patches or hot fixes ordered by date. Use the -q flag to remove patches or hot fixes in reverse chronological order by date they were installed. Type removepatch -h for usage help.
Patch Updates
Check the Esri Support Downloads page periodically for the availability of additional patches. New information about this patch will be posted here.
June 16, 2021: This patch has been re-released with a "B" version to address this issue:
BUG-000139996 - ArcGIS Dashboard does not load after installing the Portal for ArcGIS Operations Dashboard Security Patch in a 10.7.1 disconnected environment with Windows Authentication.
This version will install over the top of the original so there is no need to uninstall before installing this one.
November 23, 2021 The windows setup(s) of this patch have been updated with new digital signatures. This change addresses the possible install error:
How to identify which ArcGIS products are installed
To determine which ArcGIS products are installed, choose the appropriate version of the PatchFinder utility for your environment and run it from your local machine. PatchFinder will list all products, hot fixes, and patches installed on your local machine.
Getting Help
Domestic sites, please contact Esri Technical Support at 1-888-377-4575, if you have any difficulty installing this patch. International sites, please contact your local Esri software distributor.
Download ID:7865
Get help from ArcGIS experts
Download the Esri Support App