漏洞 ID 编号 |
BUG-000168218 |
已提交 | June 10, 2024 |
上次修改时间 | January 26, 2025 |
适用范围 | ArcGIS GIS Server |
找到的版本 | 10.9.1 |
操作系统 | Windows Server |
操作系统版本 | 2022 |
状态 | In Review
该问题正在审查中。 审查过程可确保问题包含所有必要信息、易于理解、不与现有问题重复,且为关于漏洞或增强功能的有效请求。 在此阶段,可能会联系您进行说明或提供其他信息。
|
解决办法
The problematic Database Admin User password can be updated to a working password by temporarily using Postgres Trust Authentication: PostgreSQL: Documentation: 16: 21.4. Trust Authentication
- On the ArcGIS Data Store machine, navigate to the Data Store's pg_hba.conf file (i.e. C:\arcgisdatastore\pgdata\pg_hba.conf).
- Take a backup of pg_hba.conf (i.e. create a copy of this file and rename with .bak extension, pg_hba.conf.bak).
- Edit the pg_hba.conf file to add the following line/value at the uppermost position:
- hostssl all all 127.0.0.1/32 trust

- This entry specifically allows for local connections to be made to postgres using whichever database username is specified. In other words, this entry will allow connection to postgres as the Database Admin User while ignoring (and thus overcoming) the problematic password. For more information, see PostgreSQL: Documentation: 16: 21.4. Trust Authentication.
- Save the pg_hba.conf file.
- Using Data Store ArcGIS Data Store command utility reference—Portal for ArcGIS | Documentation for ArcGIS Enterprise, and execute listadminusers. This will now succeed, and the Database Admin User username and password will now be displayed. Note the Database Admin User (i.e. adm_2ztay).

- Using Data Store ArcGIS Data Store command utility reference—Portal for ArcGIS | Documentation for ArcGIS Enterprise, execute changepassword for the Database Admin User, while specifying a password that we do not expect to be problematic (i.e. potato). Once completed, execute listadminusers to verify the password has been changed successfully.

- Revert the Data Store pg_hba.conf file to it's original state, or to the backup copy.
- Note, this step is important to ensure the Data Store remains secure.
The Database Admin User should now be able to execute normal commands and functionality should be restored.
重现步骤