DSA-2021-274: Dell EMC Data Domain Security Update for Apache Log4j Remote Code Execution Vulnerability (CVE-2021-44228 and CVE-2021-45046)
Oversigt: Dell EMC Data Domain workaround and mitigation is available before remediation for the Apache Log4j Remote Code Execution Vulnerability that may be exploited by malicious users to compromise the affected system. Dell recommends implementing this remediation as soon as possible in light of the critical severity of the vulnerability. ...
Denne artikel gælder for
Denne artikel gælder ikke for
Denne artikel er ikke knyttet til et bestemt produkt.
Det er ikke alle produktversioner, der er identificeret i denne artikel.
Virkning
Critical
Oplysninger
| Third-party Component | CVEs | More information |
| Apache Log4J | CVE-2021-44228 | Apache Log4j Remote Code Execution |
| CVE-2021-45046 | Apache Log4j Remote Code Execution |
| Third-party Component | CVEs | More information |
| Apache Log4J | CVE-2021-44228 | Apache Log4j Remote Code Execution |
| CVE-2021-45046 | Apache Log4j Remote Code Execution |
Berørte produkter og udbedring
|
|
Løsninger og afhjælpninger
Disable UI using command "adminaccess disable HTTP" and "adminaccess disable HTTPS"
See Dell KB article 126375: PowerProtect and Data Domain core documents to view the Dell EMC DD OS Command Reference Guide for details.
Revisionshistorik
| Revision | Date | Description |
| 1.0 | 2021-12-15 | Initial Release |
| 1.1 | 2021-12-17 | Update released |
| 1.2 | 2021-12-29 | updated versions and workaround section |
| 1.3 | 2022-01-04 | Added not impacted products |
| 1.4 | 2022-01-28 | Added updated version 7.7.1.0 |
| 1.5 | 2022-04-20 | Updated Affected Products table |
Relaterede oplysninger
Ansvarsfraskrivelse
Berørte produkter
Data Domain, Data Domain, Product Security InformationArtikelegenskaber
Artikelnummer: 000194503
Artikeltype: Dell Security Advisory
Senest ændret: 12 maj 2026
Find svar på dine spørgsmål fra andre Dell-brugere
Supportservices
Kontrollér, om din enhed er dækket af supportservices.