Patches and updates
ArcGIS Server Map Service Security 2022 Update 1 Patch
Summary
Description
Esri® announces the ArcGIS Server Map Service Security 2022 Update 1 Patch. Esri recommends that all customers using ArcGIS Server 10.8.1 and 10.7.1 apply this patch. This patch deals specifically with the issue listed below under Issues Addressed with this patch.
Issues Addressed with this patch
- BUG-000142376 - Reflected Cross-Site Scripting (XSS) vulnerability in ArcGIS Server.
Installing this patch on Windows
Installation Steps:
This patch should be installed on all ArcGIS Server installations related to the ArcGIS Server site.
The ArcGIS product listed in the table must be installed on your system before you can install a patch. Each patch setup is specific to the ArcGIS product in the list. To determine which products are installed on your system, please see the How to identify which ArcGIS products are installed section. Esri recommends that you install the patch for each product that is on your system.
- Download the appropriate file to a location other than your ArcGIS installation location.
ArcGIS Enterprise ArcGIS Server 10.8.1 ArcGIS-1081-S-MSS2022U1-Patch.msp Checksum
(SHA256)6052B31B8DDD0F95AE7C46D3C6A1373141D5AD1BCC547838600C6B329F6B0804
ArcGIS Server 10.7.1 ArcGIS-1071-S-MSS2022U1-Patch.msp Checksum
(SHA256)FB269B5C0B3E6716BDD50B96B099334CC2550E92690987B3479F884817467792
- Make sure you have write access to your ArcGIS installation location.
- Double-click ArcGIS-<Version>-S-MSS2022U1-Patch.msp to start the setup process.
NOTE: If double clicking on the MSP file does not start the setup installation, you can start the setup installation manually by using the following command:
msiexec.exe /p [location of Patch]\ArcGIS-<Version>-S-MSS2022U1-Patch.msp
Installing this patch on Linux
Installation Steps:
Complete the following install steps as the ArcGIS Install owner. The Install owner is the owner of the arcgis folder. This patch should be installed on all ArcGIS Server installations related to the ArcGIS Server site.
The ArcGIS product listed in the table must be installed on your system before you can install a patch. Each patch setup is specific to the ArcGIS product in the list. To determine which products are installed on your system, please see the How to identify which ArcGIS products are installed section. Esri recommends that you install the patch for each product that is on your system.
- Download the appropriate file to a location other than your ArcGIS installation location.
ArcGIS Enterprise ArcGIS Server 10.8.1 ArcGIS-1081-S-MSS2022U1-Patch-linux.tar Checksum
(SHA256)BA6F59A274F66F4422C674323F9EA110207D2248C917070E8006405448303D41
ArcGIS Server 10.7.1 ArcGIS-1071-S-MSS2022U1-Patch-linux.tar Checksum
(SHA256)57A0734262F22513127AFA258EF59A94130A40B61329BDEA633362DC6B92C9E5
- Make sure you have write access to your ArcGIS installation location, and that no one is using ArcGIS.
- Extract the specified tar file by typing:
% tar -xvf ArcGIS-<Version>-S-MSS2022U1-Patch-linux.tar
- Start the installation by typing:
% ./applypatch
This will start the dialog for the menu-driven installation procedure. Default selections are noted in parentheses ( ). To quit the installation procedure, type 'q' at any time.
Uninstalling this patch on Windows
Uninstalling this patch on Linux
To remove this patch on versions 10.7 and higher, navigate to the <Product Installation Directory>/.Setup/qfe directory and run the following script as the ArcGIS Install owner:
./removepatch.sh
The removepatch.sh script allows you to uninstall previously installed patches or hot fixes. Use the -s status flag to get the list of installed patches or hot fixes ordered by date. Use the -q flag to remove patches or hot fixes in reverse chronological order by date they were installed. Type removepatch -h for usage help.
Restart your ArcGIS services.
Patch Updates
Check the Patches and Service Packs page periodically for the availability of additional patches. New information about this patch will be posted here.
How to identify which ArcGIS products are installed
To determine which ArcGIS products are installed, choose the appropriate version of the PatchFinder utility for your environment and run it from your local machine. PatchFinder will list all products, hot fixes, and patches installed on your local machine.
Getting Help
Domestic sites, please contact Esri Technical Support at 1-888-377-4575, if you have any difficulty installing this patch. International sites, please contact your local Esri software distributor.
Download ID:8042
Get help from ArcGIS experts
Download the Esri Support App