Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000153594


DSA-2020-076: Dell EMC Integrated Data Protection Appliance Security Update for Apache Tomcat Ghostcat Vulnerability

Article Content


Impact

Critical

Details

Summary:    
The Appliance Configuration Manager (ACM) virtual machine within Dell EMC Integrated Data Protection Appliance requires a security update to address a vulnerability. 

The component is updated for the following vulnerability:    

  • CVE-2020-1938
    9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm

To search for a particular CVE, use the database s search utility at http://web.nvd.nist.gov/view/vuln/search.

The component is updated for the following vulnerability:    

  • CVE-2020-1938
    9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm

To search for a particular CVE, use the database s search utility at http://web.nvd.nist.gov/view/vuln/search.

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

Affected products:    
Dell EMC Integrated Data Protection Appliance 2.0
Dell EMC Integrated Data Protection Appliance 2.1
Dell EMC Integrated Data Protection Appliance 2.2
Dell EMC Integrated Data Protection Appliance 2.3
Dell EMC Integrated Data Protection Appliance 2.4
Dell EMC Integrated Data Protection Appliance 2.5

Remediation:
Follow the steps below to mitigate the vulnerability from the Appliance Configuration Manager (ACM) virtual machine in the Integrated Data Protection Appliance.

Log in to Appliance Configuration Manager (ACM) virtual machine using an SSH client such as PuTTY as root user and execute the following:    

  1. Stop ACM webapp:   

service dataprotection_webapp stop

  1. Edit the file  /usr/local/dataprotection/tomcat/conf/server.xml  using vi editor

vi /usr/local/dataprotection/tomcat/conf/server.xml

  1. Remove following line of AJP connector for 8009 port mentioned below:    

(Connector port="8009" protocol="AJP/1.3" redirectPort="8443" /)

  1. Save the file and exit editor.

  2. Start ACM webapp:    

service dataprotection_webapp start

Note: A hotfix will be made available for Dell EMC Integrated Data Protection Appliance version 2.5 and is targeted for Q32020.



Affected products:    
Dell EMC Integrated Data Protection Appliance 2.0
Dell EMC Integrated Data Protection Appliance 2.1
Dell EMC Integrated Data Protection Appliance 2.2
Dell EMC Integrated Data Protection Appliance 2.3
Dell EMC Integrated Data Protection Appliance 2.4
Dell EMC Integrated Data Protection Appliance 2.5

Remediation:
Follow the steps below to mitigate the vulnerability from the Appliance Configuration Manager (ACM) virtual machine in the Integrated Data Protection Appliance.

Log in to Appliance Configuration Manager (ACM) virtual machine using an SSH client such as PuTTY as root user and execute the following:    

  1. Stop ACM webapp:   

service dataprotection_webapp stop

  1. Edit the file  /usr/local/dataprotection/tomcat/conf/server.xml  using vi editor

vi /usr/local/dataprotection/tomcat/conf/server.xml

  1. Remove following line of AJP connector for 8009 port mentioned below:    

(Connector port="8009" protocol="AJP/1.3" redirectPort="8443" /)

  1. Save the file and exit editor.

  2. Start ACM webapp:    

service dataprotection_webapp start

Note: A hotfix will be made available for Dell EMC Integrated Data Protection Appliance version 2.5 and is targeted for Q32020.



Related Information


Article Properties


Affected Product

Integrated Data Protection Appliance Family

Product
PowerProtect DP4400, PowerProtect DP5300, PowerProtect DP5800, PowerProtect DP8300, PowerProtect DP8800, PowerProtect Data Protection Software, Integrated Data Protection Appliance Family, PowerProtect Data Protection Hardware , Integrated Data Protection Appliance Software, Product Security Information ...
Last Published Date

22 May 2021

Version

4

Article Type

Dell Security Advisory