laptop and a wrench

漏洞

In ArcGIS for Server 10.3, passing the username and password credentials in plain text to generate tokens through a HTTP Get request is not possible. The link provided below is of a documentation which is worded in a way that confuses customers about this workflow: http://server.arcgis.com/en/server/latest/administer/windows/enabling-token-acquisition-through-http-requests.htm Even if Get requests are enabled via the documentation, they are still unusable with credentials, which is pointless to enable them at all. It also contradicts another documentation (link provided below) that explicitly states that passing credentials in plain text through Get requests is not possible. http://server.arcgis.com/en/server/latest/administer/windows/acquiring-arcgis-tokens.htm

上次发布: August 6, 2015 ArcGIS for Server
漏洞 ID 编号 BUG-000086306
已提交March 23, 2015
上次修改时间June 5, 2024
适用范围ArcGIS for Server
找到的版本10.3
操作系统Windows OS
操作系统版本7 64 Bit
修正版本10.3.1
状态Fixed

重现步骤

漏洞 ID: BUG-000086306

软件:

  • ArcGIS for Server

当漏洞状态发生变化时获得通知

下载 Esri 支持应用程序

发现关于本主题的更多内容

获取来自 ArcGIS 专家的帮助

联系技术支持部门

下载 Esri 支持应用程序

转至下载选项