ESRI-GIS

Manufacturer: 
Environmental Systems Research Institute
Product Name: 
ArcGIS, et al.
Description: 

                                                                       ****ATTENTION****

SECURITY VULNERABILITY for ESRI ArcGIS

Please be advised that there is a vulnerability in the version of Log4j that is part of ESRI ArcGIS . Out of an abundance of caution, Esri has created Log4Shell mitigation scripts that are strongly recommended to be applied to all installations of ArcGIS Enterprise and ArcGIS Server of any version of the software.  The scripts remove the JndiLookup class which is the only mitigation measure recommended by Apache Log4j that does not require updating the Log4j version. This action fully addresses CVE-2021-44228 and CVE-2021-45046.  The scripts have been validated for versions 10.6 and above, however they should work on older versions of ArcGIS Enterprise and ArcGIS Server as well. Separate detailed instructions and scripts are available for:

Please use this link for all updates on this security vulnerability. 

https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/arcgis-software-and-cve-2021-44228-aka-log4shell-aka-logjam/

_________________________________________________________________________________________________________________________________Microsoft Azure is an Internet-scale computing and services platform hosted in data centers managed or supported by Microsoft. It is an open and flexible cloud platform that enables you to build, deploy and manage applications across a global network of Microsoft-managed datacenters. Applications can be built using any language, tool or framework, and integrated with your existing IT environment. Azure includes a number of separate features with corresponding developer services which can be used individually or together.

Environmental Systems Research Institute (ESRI) provides a large assortment of popular GIS (geographical information systems) products.  Software Central sells annual licenses for ArcGIS for Desktop Advanced, Standard or Basic, and many other ESRI products. Here is a Functionality Matrix to help you decide what to purchase based on your project's needs.

The UCLA Institute for Digital Research and Education (IDRE) GIS consultants are available to provide assistance to campus Esri users and technical support requests may be sent to the IDRE GIS Team. For more information on the available products and services, please visit the IDRE Geographic Information Systems website.

No cost student licenses are available for distribution and support by faculty teaching ArcGIS courses. For more information on the available products and services, check the Esri Software Promotion for GIS Students at Institutions with a Campus-Wide Site License website.

Esri online training is available via the ESRI Virtual University. UCLA affiliated individuals interested in signing up for the no charge courses UCLA has access to (most but not all) please visit the link above, note the course titles you require, then email those titles to Software Central for the required access information.

Esri holds an annual User Conference in San Diego in the summer. Any student from UCLA can attend any one day of the Esri User Conference at no cost with onsite registration. The student must bring their UC identification with them to the conference registration booth. No pre-registration is required.

Ordering Information: 

License terms are available via CalUsource which stores contract information for the UC and CSU systems. UCLA persons with a shibboleth login may access CalUsource, using your Single Sign On (SSO) credentials. If you receive an error message while trying to login to CalUsource, please contact support@ucprocure.zendesk.com and ask for Campus Viewer Access. Once logged in, please bookmark the site for easy future access.

Agreement Scope: 
UC-wide Agreement