メイン コンテンツに進む
  • すばやく簡単にご注文が可能
  • 注文内容の表示、配送状況をトラック
  • 会員限定の特典や割引のご利用
  • 製品リストの作成とアクセスが可能
  • 「Company Administration(会社情報の管理)」では、お使いのDell EMCのサイトや製品、製品レベルでのコンタクト先に関する情報を管理できます。

文書番号: 000194490


DSA-2021-270: Enterprise Hybrid Cloud Security Update for Apache Log4j Remote Code Execution Vulnerability (CVE-2021-44228)

概要: Enterprise Hybrid Cloud remediation is available for the Apache Log4j Remote Code Execution Vulnerability that may be exploited by malicious users to compromise the affected system. Dell recommends implementing this remediation as soon as possible in light of the critical severity of the vulnerability. ...

文書の内容


影響

Critical

詳細

Third-party Component CVE More information
Apache log4j CVE-2021-44228 Apache Log4j Remote Code Execution
DSN-2021-007: Dell Response to Apache Log4j Remote Code Execution Vulnerability 
Third-party Component CVE More information
Apache log4j CVE-2021-44228 Apache Log4j Remote Code Execution
DSN-2021-007: Dell Response to Apache Log4j Remote Code Execution Vulnerability 
デル・テクノロジーズでは、すべてのお客様に対して、CVSSベース スコアに加えて、特定のセキュリティの脆弱性に付随する潜在的な重要度に影響する可能性のある現状スコアや環境スコアも考慮することをお勧めしています。

影響を受ける製品と修復

Enterprise Hybrid Cloud 4.1.2 workflows is not impacted by this advisory, including packages Update 1 through 8.

Monitor the following advisories and apply workaround guidance and remediations as they become available:
 
CVE Addressed Products Link to Update
CVE-2021-44228 VMware vCenter Server Appliance VMSA-2021-0028.3
VMware vRealize Automation 7.x
VMware vRealize Orchestrator 7.x
VMware NSX for Data Center for vSphere 6.x
VMware vRealize Log Insight 8.x
VMware vRealize Business for Cloud 7.x
Dell EMC Data Domain OS DSA-2021-274
 
Dell EMC Avamar DSA-2021-277
Dell EMC VxRail DSA-2021-265
VxBlock See vce6771 (requires customer login)
Dell EMC Unity Monitor Knowledge Baste Article 194414 for advisory publication: https://www.dell.com/support/kbdoc/en-uk/000194414/dell-response-to-apache-log4j-remote-code-execution-vulnerability
Dell EMC RecoverPoint for Virtual Machines DSA-2021-284

 Note: Dell EMC RecoverPoint for Virtual Machines plugin is not impacted by this advisory, all packages Update 1 through 8 are covered.
Enterprise Hybrid Cloud 4.1.2 workflows is not impacted by this advisory, including packages Update 1 through 8.

Monitor the following advisories and apply workaround guidance and remediations as they become available:
 
CVE Addressed Products Link to Update
CVE-2021-44228 VMware vCenter Server Appliance VMSA-2021-0028.3
VMware vRealize Automation 7.x
VMware vRealize Orchestrator 7.x
VMware NSX for Data Center for vSphere 6.x
VMware vRealize Log Insight 8.x
VMware vRealize Business for Cloud 7.x
Dell EMC Data Domain OS DSA-2021-274
 
Dell EMC Avamar DSA-2021-277
Dell EMC VxRail DSA-2021-265
VxBlock See vce6771 (requires customer login)
Dell EMC Unity Monitor Knowledge Baste Article 194414 for advisory publication: https://www.dell.com/support/kbdoc/en-uk/000194414/dell-response-to-apache-log4j-remote-code-execution-vulnerability
Dell EMC RecoverPoint for Virtual Machines DSA-2021-284

 Note: Dell EMC RecoverPoint for Virtual Machines plugin is not impacted by this advisory, all packages Update 1 through 8 are covered.

回避策と緩和策

Follow workaround and mitigation information in articles and advisories linked in the Affected Products and Remediation section.

変更履歴

RevisionDateDescription
1.02021-12-14Initial Release
1.12021-12-17Updated Content

関連情報


文書のプロパティ


影響を受ける製品

Enterprise Hybrid Cloud, Enterprise Hybrid Cloud

製品

Product Security Information

最後に公開された日付

17 12月 2021

バージョン

2

文書の種類

Dell Security Advisory