laptop and a wrench

漏洞

There is no edit if a user enters the incorrect domain name (AVWOLD\ (refer to note 1) instead of AVWORLD\ (refer to note 1)) when accessing a secure service in ArcGIS for Server 10.3 using Windows AD users/roles with the REST page accessed. So long as the users provide a valid username and password, they are capable of accessing a secured service regardless to the accuracy of the domain name.

上次发布: February 24, 2022 ArcGIS for Server
漏洞 ID 编号 BUG-000085803
已提交March 3, 2015
上次修改时间June 5, 2024
适用范围ArcGIS for Server
找到的版本10.3
操作系统Windows OS
操作系统版本2012 64 Bit
状态Will Not Be Addressed

附加信息

This issue was logged against a version of the software which is no longer supported, and has not had activity in some time. We apologize that we were unable to address this issue within the current product life cycle. If the issue continues to affect your work in a supported release, please contact Technical Support.

解决办法

Type in the correct domain name or just use a valid username and password as the domain name. Once specified in the Server Security configuration, it is not validated again.

重现步骤

漏洞 ID: BUG-000085803

软件:

  • ArcGIS for Server

当漏洞状态发生变化时获得通知

下载 Esri 支持应用程序

发现关于本主题的更多内容

获取来自 ArcGIS 专家的帮助

联系技术支持部门

下载 Esri 支持应用程序

转至下载选项