ArcGIS Blog

Administration

ArcGIS Enterprise

Portal for ArcGIS 10.8.1 Enterprise Sites Patch 2 available.

By RandallWilliams

A moderate priority Cross Site Scripting (XSS) vulnerability has been discovered in ArcGIS Enterprise Sites Builder version 10.8.1.

[#BUG-000135364 XSS in ArcGIS Enterprise Sites (iframe card) ]

This is a moderate priority issue with a CVSSv3: 5.4.

Esri recommends all ArcGIS Enterprise administrators install this patch by using the ArcGIS Enterprise “Patch Notification” tool or by downloading the appropriate patch for your ArcGIS Enterprise site from the Portal for ArcGIS 10.8.1 Enterprise Sites Patch 2 patch page.
Be sure to subscribe to the RSS feed on the ArcGIS Trust Center for timely notifications regarding trends and issues related to security issues that impact the ArcGIS Platform.

How To: Schedule Automatic Updates for ArcGIS Enterprise

Share this article

Subscribe
Notify of
0 Comments
Oldest
Newest
Inline Feedbacks
View all comments