{"id":1474292,"date":"2022-02-11T09:00:49","date_gmt":"2022-02-11T17:00:49","guid":{"rendered":"https:\/\/www.esri.com\/arcgis-blog\/?post_type=blog&#038;p=1474292"},"modified":"2023-05-25T17:57:21","modified_gmt":"2023-05-26T00:57:21","slug":"arcgis-enterprise-log4j-security-patches-available","status":"publish","type":"blog","link":"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/arcgis-enterprise-log4j-security-patches-available","title":{"rendered":"ArcGIS Enterprise Log4j Security Patches Available"},"author":3911,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","format":"standard","meta":{"_acf_changed":false,"_searchwp_excluded":""},"categories":[37501],"tags":[24081,24361,764192,241722],"industry":[],"product":[36571,763582],"class_list":["post-1474292","blog","type-blog","status-publish","format-standard","hentry","category-administration","tag-ssamymlgp","tag-patch","tag-securitypatch","tag-ssamlymlgp","product-arcgis-enterprise","product-trust-arcgis"],"acf":{"short_description":"Detailed information about what Log4j CVE's are addressed and how the issues are addressed.","flexible_content":[{"acf_fc_layout":"content","content":"<p><em>Last updated:<\/em> 5\/25\/2023<\/p>\n<p>Critical security vulnerabilities in Apache Log4j may allow escalation of privilege or denial of service. Apache Log4j is used across ArcGIS Enterprise components, therefore Esri has released separate updates for ArcGIS Server, Portal for ArcGIS, and ArcGIS Data Store to resolve these vulnerabilities.<\/p>\n<p>Esri initially released scripts to quickly mitigate the critical Log4j vulnerabilities CVE-2021-44228 and CVE-2021-45046. The software patches described below remediate these vulnerabilities as well as other Log4j vulnerabilities listed in this announcement.<\/p>\n<p><strong>ArcGIS Enterprise 11.1<\/strong><\/p>\n<p>Does not require Log4j patching or any special configuration constraints and is therefore the ideal remediation &#8211; For additional information <a href=\"https:\/\/www.esri.com\/arcgis-blog\/products\/arcgis-enterprise\/administration\/arcgis-software-and-cve-2021-44228-aka-log4shell-aka-logjam\/\">see the cross-product Log4j announcement<\/a>.<\/p>\n<p><strong>ArcGIS Enterprise Patches:`<\/strong><\/p>\n<ul>\n<li>Portal for ArcGIS <a href=\"https:\/\/support.esri.com\/en\/download\/7974\">10.6<\/a>, <a href=\"https:\/\/support.esri.com\/en\/download\/7973\">10.6.1<\/a>, <a href=\"https:\/\/support.esri.com\/en\/download\/7972\">10.7.1<\/a>, <a href=\"https:\/\/support.esri.com\/en\/download\/7969\">10.8.1<\/a>, <a href=\"https:\/\/support.esri.com\/en\/download\/7971\">10.9<\/a>, <a href=\"https:\/\/support.esri.com\/en\/download\/7970\">10.9.1<\/a><strong><br \/>\n&#8211; Important Note<\/strong>: New Portal for ArcGIS patches (version B) were released on April 20, 2022.\u00a0 Click the corresponding product version above for details.<\/li>\n<li>ArcGIS Server <a href=\"https:\/\/support.esri.com\/en\/download\/7977\">10.6<\/a>, <a href=\"https:\/\/support.esri.com\/en\/download\/7966\">10.6.1<\/a>, <a href=\"https:\/\/support.esri.com\/en\/download\/7975\">10.7.1<\/a>, <a href=\"https:\/\/support.esri.com\/en\/download\/7965\">10.8.1<\/a>, <a href=\"https:\/\/support.esri.com\/en\/download\/7976\">10.9<\/a>, <a href=\"https:\/\/support.esri.com\/en\/download\/7963\">10.9.1 <\/a><strong><br \/>\n&#8211; Important Note<\/strong>: New ArcGIS Server patches (version B) were released on April 11, 2022 to prevent <a href=\"https:\/\/support.esri.com\/en\/bugs\/nimbus\/QlVHLTAwMDE0ODE0Ng==\">BUG-000148146<\/a> on some AWS (Amazon Web Services) deployments. Click the corresponding product version above for details.<\/li>\n<\/ul>\n<ul>\n<li>ArcGIS Data Store <a href=\"https:\/\/support.esri.com\/en\/download\/7985\">10.6<\/a>, <a href=\"https:\/\/support.esri.com\/en\/download\/7984\">10.6.1<\/a>, <a href=\"https:\/\/support.esri.com\/en\/download\/7983\">10.7.1<\/a>, <a href=\"https:\/\/support.esri.com\/en\/download\/7982\">10.8.1<\/a>, <a href=\"https:\/\/support.esri.com\/en\/download\/7981\">10.9<\/a>, <a href=\"https:\/\/support.esri.com\/en\/download\/7980\">10.9.1<\/a><\/li>\n<li>ArcGIS GeoEvent Server <a href=\"https:\/\/support.esri.com\/en\/download\/8003\">10.6<\/a>, <a href=\"https:\/\/support.esri.com\/en\/download\/8002\">10.6.1<\/a>, <a href=\"https:\/\/support.esri.com\/en\/download\/8001\">10.7.1<\/a>, <a href=\"https:\/\/support.esri.com\/en\/download\/8000\">10.8.1<\/a>, <a href=\"https:\/\/supportwww.esri.com\/en\/download\/7997\">10.9<\/a>, <a href=\"https:\/\/support.esri.com\/en\/download\/7998\">10.9.1<\/a><\/li>\n<li>ArcGIS Workflow Manager Server <a href=\"https:\/\/support.esri.com\/en\/download\/8020\">10.9.1<\/a><\/li>\n<li>ArcGIS GeoEnrichment Server <a href=\"https:\/\/support.esri.com\/en\/download\/8001\">10.7.1<\/a>, <a href=\"https:\/\/support.esri.com\/en\/download\/8026\">10.8.1<\/a>, <a href=\"https:\/\/support.esri.com\/en\/download\/8025\">10.9<\/a>, <a href=\"https:\/\/support.esri.com\/en\/download\/7999\" target=\"_blank\" rel=\"noopener\" aria-describedby=\"new-window\">10.9.1<\/a><\/li>\n<li>ArcGIS Data Interoperability for Server <a href=\"https:\/\/support.esri.com\/en\/download\/8017\" target=\"_blank\" rel=\"noopener\" aria-describedby=\"new-window\">10.6<\/a>,\u00a0<a href=\"https:\/\/support.esri.com\/en\/download\/8016\" target=\"_blank\" rel=\"noopener\" aria-describedby=\"new-window\">10.6.1<\/a>,\u00a0<a href=\"https:\/\/support.esri.com\/en\/download\/8015\" target=\"_blank\" rel=\"noopener\" aria-describedby=\"new-window\">10.7.1<\/a>,\u00a0<a href=\"https:\/\/support.esri.com\/en\/download\/8014\" target=\"_blank\" rel=\"noopener\" aria-describedby=\"new-window\">10.8.1<\/a>,\u00a0<a href=\"https:\/\/support.esri.com\/en\/download\/8013\" target=\"_blank\" rel=\"noopener\" aria-describedby=\"new-window\">10.9<\/a>,\u00a0<a href=\"https:\/\/support.esri.com\/en\/download\/8012\" target=\"_blank\" rel=\"noopener\" aria-describedby=\"new-window\">10.9.1<\/a><\/li>\n<li>ArcGIS Notebook Server <a href=\"https:\/\/support.esri.com\/en\/download\/8010\">10.7.1<\/a>, <a href=\"https:\/\/support.esri.com\/en\/download\/8009\">10.8.1<\/a>, <a href=\"https:\/\/support.esri.com\/en\/download\/8008\">10.9<\/a>, <a href=\"https:\/\/support.esri.com\/en\/download\/8004\">10.9.1<\/a><\/li>\n<li>ArcGIS Enterprise on Kubernetes <a href=\"https:\/\/enterprise-k8s.arcgis.com\/en\/latest\/introduction\/release-notes.htm\">10.9.1.1611<\/a><\/li>\n<\/ul>\n<p>See <a href=\"https:\/\/support.esri.com\/en\/download\/7964\">ArcGIS Enterprise Log4j Patch Summary Page<\/a><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Patch Details:<\/strong><\/p>\n<ul>\n<li>All Log4j 2.x components are updated to version 2.17.1, the latest version available at the time of this patch release.\n<ul>\n<li>For technical reasons, modified versions of some older Log4j 2.x files are left behind after patching. All Java classes have been removed from these files (considered \u201cempty\u201d) and only include metadata pointing to the new version 2.17.1 files. The older files that are left behind cannot be deleted without disrupting application functionality.<\/li>\n<li>These emptied files will be entirely removed upon installation of the next ArcGIS Enterprise product release.<\/li>\n<li>Security scanners that are inappropriately configured to detect vulnerable components solely based on file version numbers may detect false positives after these patches are applied.<\/li>\n<\/ul>\n<\/li>\n<li><strong>\u00a0<\/strong>All Log4j 1.2.x components have had vulnerable classes removed OR non-vulnerable Log4j bridge implemented.\n<ul>\n<li>Mitigated Log4j 1.2.x components are included with this patch due to dependencies on larger frameworks where Log4j bridge not implemented.<\/li>\n<li>Esri will be removing Log4j 1.2.x components as part of the next product release, which includes further usage of the <a href=\"https:\/\/logging.apache.org\/log4j\/2.x\/manual\/migration.html\">Log4j 1.x bridge<\/a>, allowing removal of the old code, while providing compatibility for frameworks that don&#8217;t support Log4j 2.x directly yet.<\/li>\n<li>Customers can use a validation tool such as Logpresso\u2019s free Log4j-scan tool as described further in our <a href=\"https:\/\/www.esri.com\/arcgis-blog\/products\/arcgis-enterprise\/administration\/arcgis-software-and-cve-2021-44228-aka-log4shell-aka-logjam\/\">cross-product Log4j announcement<\/a> to confirm your files have been mitigated.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><strong>\u00a0<\/strong><strong>\u00a0<\/strong><\/p>\n<p><strong>Log4j vulnerabilities addressed in these patches include:<\/strong><\/p>\n<p><em>CVEID: <\/em><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-44228\"><em>CVE-2021-44228<\/em><\/a><em> (Non-Esri issued 12\/9\/2021)<\/em><\/p>\n<p>Description: JNDI features in Apache Log4j2 may allow an authenticated user to potentially enable escalation of privilege via network access.<\/p>\n<p>CVSS Base Score: 10.0 Critical<\/p>\n<p>CVSS Vector:\u00a0 CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:H\/I:H\/A:H<\/p>\n<p>ArcGIS Enterprise Exploit Code Maturity: Unproven<\/p>\n<p>&nbsp;<\/p>\n<p><em>CVEID: <\/em><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-45046\"><em>CVE-2021-45046<\/em><\/a><em> (Non-Esri issued 12\/14\/2021)<\/em><\/p>\n<p>Description: It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations.<\/p>\n<p>CVSS Base Score: 9.0 Critical<\/p>\n<p>CVSS Vector:\u00a0 CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:C\/C:H\/I:H\/A:H<\/p>\n<p>ArcGIS Enterprise Exploit Code Maturity: Unproven<\/p>\n<p>&nbsp;<\/p>\n<p><em>CVEID:<\/em> <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-4104\"><em>CVE- 2021-4104<\/em><\/a><em> (Non-Esri issued 12\/14\/2021)<\/em><\/p>\n<p>Description: JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration.<\/p>\n<p>CVSS Base Score: 7.5 HIGH<\/p>\n<p>CVSS Vector:\u00a0 CVSS:3.1\/AV:N\/AC:H\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H<\/p>\n<p>ArcGIS Enterprise Exploit Code Maturity: Unproven<\/p>\n<p>&nbsp;<\/p>\n<p><em>CVEID: <\/em><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-45105\"><em>CVE-2021-45105<\/em><\/a><em> (Non-Esri issued 12\/18\/2021)<\/em><\/p>\n<p>Description: Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups.<\/p>\n<p>CVSS Base Score: 5.9 MEDIUM<\/p>\n<p>CVSS Vector:\u00a0 CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:H<\/p>\n<p>ArcGIS Enterprise Exploit Code Maturity: Unproven<\/p>\n<p>&nbsp;<\/p>\n<p><em>CVEID: <\/em><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-44832\"><em>CVE-2021-44832<\/em><\/a><em> (Non-Esri issued 12\/28\/2021)<\/em><\/p>\n<p>Description: Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server.<\/p>\n<p>CVSS Base Score: 6.6 MEDIUM<\/p>\n<p>CVSS Vector:\u00a0 CVSS:3.1\/AV:N\/AC:H\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H<\/p>\n<p>ArcGIS Enterprise Exploit Code Maturity: Unproven<\/p>\n<p>&nbsp;<\/p>\n<p><em>CVEID: <\/em><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-23305\"><em>CVE-2022-23305<\/em><\/a><em> (Non-Esri issued 1\/18\/2022)<\/em><\/p>\n<p>Description: By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout.<\/p>\n<p>CVSS Base Score: 9.8 CRITICAL<\/p>\n<p>CVSS Vector: CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H<\/p>\n<p>&nbsp;<\/p>\n<p><em>CVEID: <\/em><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-23302\"><em>CVE-2022-23302<\/em><\/a><em> (Non-Esri issued 1\/18\/2022)<\/em><\/p>\n<p>Description: JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to.<\/p>\n<p>CVSS Base Score: 8.8 HIGH<\/p>\n<p>CVSS Vector: CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H<\/p>\n<p>ArcGIS Enterprise Exploit Code Maturity: Unproven<\/p>\n<p>&nbsp;<\/p>\n<p><em>CVEID: <\/em><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-23307\"><em>CVE-2022-23307<\/em><\/a><em> (Non-Esri issued 1\/18\/2022)<\/em><\/p>\n<p>Description: CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.<\/p>\n<p>CVSS Base Score: 9.8 CRITICAL<\/p>\n<p>CVSS Vector: CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H<\/p>\n<p>ArcGIS Enterprise Exploit Code Maturity: Unproven<\/p>\n<p>&nbsp;<\/p>\n<p><em>CVEID: <\/em><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-9488\"><em>CVE-2020-9488<\/em><\/a><em> (Non-Esri issued 4\/27\/2020)<\/em><\/p>\n<p>Description:\u00a0 Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender.<\/p>\n<p>CVSS Base Score: 3.7 LOW<\/p>\n<p>CVSS Vector:\u00a0 CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N<\/p>\n<p>ArcGIS Enterprise Exploit Code Maturity: Unproven<\/p>\n<p>&nbsp;<\/p>\n<p><em>CVEID: <\/em><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-17571\"><em>CVE-2019-17571<\/em><\/a><em> (Non-Esri issued 12\/20\/2019)<\/em><\/p>\n<p>Description: Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data.<\/p>\n<p>CVSS Base Score: 9.8 CRITICAL<\/p>\n<p>CVSS Vector:\u00a0 CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H<\/p>\n<p>ArcGIS Enterprise Exploit Code Maturity: Unproven<\/p>\n<p>&nbsp;<\/p>\n<p><em>CVEID: <\/em><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-5645\"><em>CVE-2017-5645<\/em><\/a><em> (Non-Esri issued 4\/17\/2017)<\/em><\/p>\n<p>Description: In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.<\/p>\n<p>CVSS Base Score: 9.8 CRITICAL<\/p>\n<p>CVSS Vector:\u00a0 CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H<\/p>\n<p>ArcGIS Enterprise Exploit Code Maturity: Unproven<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Cross-Product Guidance:<\/strong><\/p>\n<p>Due to the level of concern with Log4j vulnerabilities across industries, Esri provides cross-product guidance for Log4j concerns as a separate announcement <a href=\"https:\/\/www.esri.com\/arcgis-blog\/products\/arcgis-enterprise\/administration\/arcgis-software-and-cve-2021-44228-aka-log4shell-aka-logjam\/\">here<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Acknowledgements:<\/strong><\/p>\n<p>These issues were found externally and were publicly disclosed via the <a href=\"https:\/\/nvd.nist.gov\/\">National Vulnerability Database<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li><em>Esri Software Security &amp; Privacy Team<\/em><\/li>\n<\/ul>\n"}],"related_articles":"","card_image":"https:\/\/www.esri.com\/arcgis-blog\/app\/uploads\/2022\/02\/SA-Enterprise1.gif","wide_image":false,"authors":[{"ID":3911,"user_firstname":"Michael","user_lastname":"Young","nickname":"Michael Young","user_nicename":"myoung1000","display_name":"Michael Young","user_email":"myoung@esri.com","user_url":"http:\/\/trust.arcgis.com","user_registered":"2018-03-02 00:15:29","user_description":"","user_avatar":"<img data-del=\"avatar\" src='https:\/\/www.esri.com\/arcgis-blog\/app\/uploads\/2021\/12\/SSP-213x200.jpg' class='avatar pp-user-avatar avatar-96 photo ' height='96' width='96'\/>"},{"ID":5311,"user_firstname":"Randall","user_lastname":"Williams","nickname":"Randall Williams","user_nicename":"randallwilliams","display_name":"Randall Williams","user_email":"randall_williams@esri.com","user_url":"https:\/\/trust.arcgis.com","user_registered":"2018-03-02 00:17:03","user_description":"","user_avatar":"<img data-del=\"avatar\" src='https:\/\/www.esri.com\/arcgis-blog\/app\/uploads\/2018\/08\/softwaresecurity.png' class='avatar pp-user-avatar avatar-96 photo ' height='96' width='96'\/>"}]},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.9 (Yoast SEO v25.9) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>ArcGIS Enterprise Log4j Security Patches Available<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/arcgis-enterprise-log4j-security-patches-available\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"ArcGIS Enterprise Log4j Security Patches Available\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/arcgis-enterprise-log4j-security-patches-available\" \/>\n<meta property=\"og:site_name\" content=\"ArcGIS Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/esrigis\/\" \/>\n<meta property=\"article:modified_time\" content=\"2023-05-26T00:57:21+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@ESRI\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/arcgis-enterprise-log4j-security-patches-available#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/arcgis-enterprise-log4j-security-patches-available\"},\"author\":{\"name\":\"Michael Young\",\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/#\/schema\/person\/b1e77881551053100a9cef9dba632678\"},\"headline\":\"ArcGIS Enterprise Log4j Security Patches Available\",\"datePublished\":\"2022-02-11T17:00:49+00:00\",\"dateModified\":\"2023-05-26T00:57:21+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/arcgis-enterprise-log4j-security-patches-available\"},\"wordCount\":7,\"publisher\":{\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/#organization\"},\"keywords\":[\"ArcGIS Trust Center\",\"Patch\",\"SecurityPatch\",\"SSAMLYMLGP\"],\"articleSection\":[\"Administration\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/arcgis-enterprise-log4j-security-patches-available\",\"url\":\"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/arcgis-enterprise-log4j-security-patches-available\",\"name\":\"ArcGIS Enterprise Log4j Security Patches Available\",\"isPartOf\":{\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/#website\"},\"datePublished\":\"2022-02-11T17:00:49+00:00\",\"dateModified\":\"2023-05-26T00:57:21+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/arcgis-enterprise-log4j-security-patches-available#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/arcgis-enterprise-log4j-security-patches-available\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/arcgis-enterprise-log4j-security-patches-available#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.esri.com\/arcgis-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"ArcGIS Enterprise Log4j Security Patches Available\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/#website\",\"url\":\"https:\/\/www.esri.com\/arcgis-blog\/\",\"name\":\"ArcGIS Blog\",\"description\":\"Get insider info from Esri product teams\",\"publisher\":{\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.esri.com\/arcgis-blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/#organization\",\"name\":\"Esri\",\"url\":\"https:\/\/www.esri.com\/arcgis-blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.esri.com\/arcgis-blog\/app\/uploads\/2018\/04\/Esri.png\",\"contentUrl\":\"https:\/\/www.esri.com\/arcgis-blog\/app\/uploads\/2018\/04\/Esri.png\",\"width\":400,\"height\":400,\"caption\":\"Esri\"},\"image\":{\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/esrigis\/\",\"https:\/\/x.com\/ESRI\",\"https:\/\/www.linkedin.com\/company\/5311\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/#\/schema\/person\/b1e77881551053100a9cef9dba632678\",\"name\":\"Michael Young\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.esri.com\/arcgis-blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/www.esri.com\/arcgis-blog\/app\/uploads\/2021\/12\/SSP-213x200.jpg\",\"contentUrl\":\"https:\/\/www.esri.com\/arcgis-blog\/app\/uploads\/2021\/12\/SSP-213x200.jpg\",\"caption\":\"Michael Young\"},\"sameAs\":[\"http:\/\/trust.arcgis.com\"],\"url\":\"https:\/\/www.esri.com\/arcgis-blog\/author\/myoung1000\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"ArcGIS Enterprise Log4j Security Patches Available","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/arcgis-enterprise-log4j-security-patches-available","og_locale":"en_US","og_type":"article","og_title":"ArcGIS Enterprise Log4j Security Patches Available","og_url":"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/arcgis-enterprise-log4j-security-patches-available","og_site_name":"ArcGIS Blog","article_publisher":"https:\/\/www.facebook.com\/esrigis\/","article_modified_time":"2023-05-26T00:57:21+00:00","twitter_card":"summary_large_image","twitter_site":"@ESRI","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/arcgis-enterprise-log4j-security-patches-available#article","isPartOf":{"@id":"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/arcgis-enterprise-log4j-security-patches-available"},"author":{"name":"Michael Young","@id":"https:\/\/www.esri.com\/arcgis-blog\/#\/schema\/person\/b1e77881551053100a9cef9dba632678"},"headline":"ArcGIS Enterprise Log4j Security Patches Available","datePublished":"2022-02-11T17:00:49+00:00","dateModified":"2023-05-26T00:57:21+00:00","mainEntityOfPage":{"@id":"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/arcgis-enterprise-log4j-security-patches-available"},"wordCount":7,"publisher":{"@id":"https:\/\/www.esri.com\/arcgis-blog\/#organization"},"keywords":["ArcGIS Trust Center","Patch","SecurityPatch","SSAMLYMLGP"],"articleSection":["Administration"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/arcgis-enterprise-log4j-security-patches-available","url":"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/arcgis-enterprise-log4j-security-patches-available","name":"ArcGIS Enterprise Log4j Security Patches Available","isPartOf":{"@id":"https:\/\/www.esri.com\/arcgis-blog\/#website"},"datePublished":"2022-02-11T17:00:49+00:00","dateModified":"2023-05-26T00:57:21+00:00","breadcrumb":{"@id":"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/arcgis-enterprise-log4j-security-patches-available#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/arcgis-enterprise-log4j-security-patches-available"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/arcgis-enterprise-log4j-security-patches-available#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.esri.com\/arcgis-blog\/"},{"@type":"ListItem","position":2,"name":"ArcGIS Enterprise Log4j Security Patches Available"}]},{"@type":"WebSite","@id":"https:\/\/www.esri.com\/arcgis-blog\/#website","url":"https:\/\/www.esri.com\/arcgis-blog\/","name":"ArcGIS Blog","description":"Get insider info from Esri product teams","publisher":{"@id":"https:\/\/www.esri.com\/arcgis-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.esri.com\/arcgis-blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.esri.com\/arcgis-blog\/#organization","name":"Esri","url":"https:\/\/www.esri.com\/arcgis-blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.esri.com\/arcgis-blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.esri.com\/arcgis-blog\/app\/uploads\/2018\/04\/Esri.png","contentUrl":"https:\/\/www.esri.com\/arcgis-blog\/app\/uploads\/2018\/04\/Esri.png","width":400,"height":400,"caption":"Esri"},"image":{"@id":"https:\/\/www.esri.com\/arcgis-blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/esrigis\/","https:\/\/x.com\/ESRI","https:\/\/www.linkedin.com\/company\/5311\/"]},{"@type":"Person","@id":"https:\/\/www.esri.com\/arcgis-blog\/#\/schema\/person\/b1e77881551053100a9cef9dba632678","name":"Michael Young","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.esri.com\/arcgis-blog\/#\/schema\/person\/image\/","url":"https:\/\/www.esri.com\/arcgis-blog\/app\/uploads\/2021\/12\/SSP-213x200.jpg","contentUrl":"https:\/\/www.esri.com\/arcgis-blog\/app\/uploads\/2021\/12\/SSP-213x200.jpg","caption":"Michael Young"},"sameAs":["http:\/\/trust.arcgis.com"],"url":"https:\/\/www.esri.com\/arcgis-blog\/author\/myoung1000"}]}},"text_date":"February 11, 2022","author_name":"Multiple Authors","author_page":"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/arcgis-enterprise-log4j-security-patches-available","custom_image":"https:\/\/www.esri.com\/arcgis-blog\/app\/uploads\/2025\/08\/Newsroom-Keyart-Wide-1920-x-1080.jpg","primary_product":"ArcGIS Trust Center","tag_data":[{"term_id":24081,"name":"ArcGIS Trust Center","slug":"ssamymlgp","term_group":0,"term_taxonomy_id":24081,"taxonomy":"post_tag","description":"","parent":0,"count":96,"filter":"raw"},{"term_id":24361,"name":"Patch","slug":"patch","term_group":0,"term_taxonomy_id":24361,"taxonomy":"post_tag","description":"","parent":0,"count":21,"filter":"raw"},{"term_id":764192,"name":"SecurityPatch","slug":"securitypatch","term_group":0,"term_taxonomy_id":764192,"taxonomy":"post_tag","description":"","parent":0,"count":2,"filter":"raw"},{"term_id":241722,"name":"SSAMLYMLGP","slug":"ssamlymlgp","term_group":0,"term_taxonomy_id":241722,"taxonomy":"post_tag","description":"","parent":0,"count":25,"filter":"raw"}],"category_data":[{"term_id":37501,"name":"Administration","slug":"administration","term_group":0,"term_taxonomy_id":37501,"taxonomy":"category","description":"","parent":0,"count":422,"filter":"raw"}],"product_data":[{"term_id":36571,"name":"ArcGIS Enterprise","slug":"arcgis-enterprise","term_group":0,"term_taxonomy_id":36571,"taxonomy":"product","description":"","parent":0,"count":972,"filter":"raw"},{"term_id":763582,"name":"ArcGIS Trust Center","slug":"trust-arcgis","term_group":0,"term_taxonomy_id":763582,"taxonomy":"product","description":"Reserved for articles authored by the ArcGIS Trust Center team","parent":36981,"count":86,"filter":"raw"}],"primary_product_link":"https:\/\/www.esri.com\/arcgis-blog\/?s=#&products=trust-arcgis","_links":{"self":[{"href":"https:\/\/www.esri.com\/arcgis-blog\/wp-json\/wp\/v2\/blog\/1474292","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.esri.com\/arcgis-blog\/wp-json\/wp\/v2\/blog"}],"about":[{"href":"https:\/\/www.esri.com\/arcgis-blog\/wp-json\/wp\/v2\/types\/blog"}],"author":[{"embeddable":true,"href":"https:\/\/www.esri.com\/arcgis-blog\/wp-json\/wp\/v2\/users\/3911"}],"replies":[{"embeddable":true,"href":"https:\/\/www.esri.com\/arcgis-blog\/wp-json\/wp\/v2\/comments?post=1474292"}],"version-history":[{"count":0,"href":"https:\/\/www.esri.com\/arcgis-blog\/wp-json\/wp\/v2\/blog\/1474292\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.esri.com\/arcgis-blog\/wp-json\/wp\/v2\/media?parent=1474292"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.esri.com\/arcgis-blog\/wp-json\/wp\/v2\/categories?post=1474292"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.esri.com\/arcgis-blog\/wp-json\/wp\/v2\/tags?post=1474292"},{"taxonomy":"industry","embeddable":true,"href":"https:\/\/www.esri.com\/arcgis-blog\/wp-json\/wp\/v2\/industry?post=1474292"},{"taxonomy":"product","embeddable":true,"href":"https:\/\/www.esri.com\/arcgis-blog\/wp-json\/wp\/v2\/product?post=1474292"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}