Impact
Critical
Details
This security patch is a set of security updates for various third-party software components that are installed on the Avamar and NetWorker nodes. The patch addresses multiple security vulnerabilities in those components. The patch applies to all Avamar and NetWorker products running on the SLES platforms listed. The products include Avamar single-node servers, multinode servers, accelerator nodes, Avamar Virtual Edition systems, Avamar VMware Image Proxy, and NetWorker Virtual Edition systems.
This security patch also updates Java JRE to version 8u291 for Avamar Server 19.3 or 19.4, Avamar Proxy 19.4, Dell Avamar NDMP Accelerator 19.3 or 19.4, and NetWorker Virtual Edition 19.4.
This security patch also updates Apache Tomcat to version 8.5.66 for Avamar Server 19.3 or 19.4.
Read more in the Release Notes:
https://dl.dell.com/content/docu104902_avamar-platform-os-security-patch-rollup-2021r1plus-release-notes.pdf?language=en_us.
This security patch is a set of security updates for various third-party software components that are installed on the Avamar and NetWorker nodes. The patch addresses multiple security vulnerabilities in those components. The patch applies to all Avamar and NetWorker products running on the SLES platforms listed. The products include Avamar single-node servers, multinode servers, accelerator nodes, Avamar Virtual Edition systems, Avamar VMware Image Proxy, and NetWorker Virtual Edition systems.
This security patch also updates Java JRE to version 8u291 for Avamar Server 19.3 or 19.4, Avamar Proxy 19.4, Dell Avamar NDMP Accelerator 19.3 or 19.4, and NetWorker Virtual Edition 19.4.
This security patch also updates Apache Tomcat to version 8.5.66 for Avamar Server 19.3 or 19.4.
Read more in the Release Notes:
https://dl.dell.com/content/docu104902_avamar-platform-os-security-patch-rollup-2021r1plus-release-notes.pdf?language=en_us.
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.
Affected Products and Remediation
CVEs Addressed |
Product |
Affected Versions |
Updated Versions |
Link to Update |
See Release Notes |
Dell Avamar |
- Dell Avamar Server hardware appliance Gen4S/Gen4T with versions 19.3 or 19.4 running SUSE Linux Enterprise 12 SP5
- Dell Avamar Virtual Edition versions 19.3 or 19.4 running SUSE Linux Enterprise 12 SP5 (including Azure and AWS deployments)
- Dell Avamar NDMP Accelerator versions 19.3 or 19.4 running SUSE Linux Enterprise 12 SP5
- Dell Avamar VMware Image Proxy versions 19.4 running SUSE Linux Enterprise 12 SP5
|
Apply the platform security patch to Avamar software version and NetWorker Virtual Edition. The following platform security patch packages are now available to be installed:
The Security Update for Avamar Virtual Edition and NetWorker Virtual Edition is customer installable. See “link to remedies” for download and installation instructions. The installation process requires shutting down the server software, rebooting all the nodes, and restarting the server software. Appropriate time must be scheduled and allocated to perform this process. Dell strongly recommends all customers upgrade at the earliest opportunity. |
To schedule platform security patch installation, or to upgrade your server, contact Dell Customer Support at https://www.dell.com/support/home/en-us. See the following KB Articles for Security Update (Rollup) Installation instructions:
|
Dell NetWorker Virtual Edition (NVE) |
- Dell NetWorker Virtual Edition (NVE) versions 19.4 running SUSE Linux Enterprise 12 SP5
|
|
Dell PowerProtect DP Series Appliance or Dell Integrated Data Protection Appliance (IDPA) |
- Dell PowerProtect DP Series Appliance or Dell Integrated Data Protection Appliance (IDPA) versions 2.6 or 2.6.1
|
CVEs Addressed |
Product |
Affected Versions |
Updated Versions |
Link to Update |
See Release Notes |
Dell Avamar |
- Dell Avamar Server hardware appliance Gen4S/Gen4T with versions 19.3 or 19.4 running SUSE Linux Enterprise 12 SP5
- Dell Avamar Virtual Edition versions 19.3 or 19.4 running SUSE Linux Enterprise 12 SP5 (including Azure and AWS deployments)
- Dell Avamar NDMP Accelerator versions 19.3 or 19.4 running SUSE Linux Enterprise 12 SP5
- Dell Avamar VMware Image Proxy versions 19.4 running SUSE Linux Enterprise 12 SP5
|
Apply the platform security patch to Avamar software version and NetWorker Virtual Edition. The following platform security patch packages are now available to be installed:
The Security Update for Avamar Virtual Edition and NetWorker Virtual Edition is customer installable. See “link to remedies” for download and installation instructions. The installation process requires shutting down the server software, rebooting all the nodes, and restarting the server software. Appropriate time must be scheduled and allocated to perform this process. Dell strongly recommends all customers upgrade at the earliest opportunity. |
To schedule platform security patch installation, or to upgrade your server, contact Dell Customer Support at https://www.dell.com/support/home/en-us. See the following KB Articles for Security Update (Rollup) Installation instructions:
|
Dell NetWorker Virtual Edition (NVE) |
- Dell NetWorker Virtual Edition (NVE) versions 19.4 running SUSE Linux Enterprise 12 SP5
|
|
Dell PowerProtect DP Series Appliance or Dell Integrated Data Protection Appliance (IDPA) |
- Dell PowerProtect DP Series Appliance or Dell Integrated Data Protection Appliance (IDPA) versions 2.6 or 2.6.1
|
Related Information
Dell Security Advisories and Notices
Dell Vulnerability Response Policy
CVSS Scoring Guide