DSA-2023-036: Dell Avamar Server and Avamar Virtual Edition Security Update for Apache Struts Vulnerability
Summary: Avamar Server and Avamar Virtual Edition remediation is available for the Apache Struts Vulnerability that may be exploited by malicious users to compromise the affected system.
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Impact
Critical
Details
| Third-party Component | CVEs | More information |
| Apache Struts | CVE-2021-31805 | https://nvd.nist.gov/vuln/detail/CVE-2021-31805 |
Affected Products & Remediation
| Product | Affected Version | Updated Versions | Update Link |
| Avamar Server, Avamar Virtual Edition | 19.3, 19.4, and 19.7 | 19.8 | https://dl.dell.com/downloads/678J1_Avamar-19.8-for-Server-and-AVE-Upgrades.avp |
| Avamar Server, Avamar Virtual Edition | 19.7 | 19.7 with the latest 19.7 MC Cumulative Hotfix for Avamar Server and Avamar Virtual Edition | Support for Avamar | Drivers & Downloads | Dell US |
| Avamar Server, Avamar Virtual Edition | 19.4 | 19.4 with the latest 19.4 MC Cumulative Hotfix for Avamar Server and Avamar Virtual Edition | Support for Avamar | Drivers & Downloads | Dell US |
| PowerProtect DP Series Appliance (IDPA) |
I2.7.x and 2.6.x | 2.7.2 / 2.7.3 with the aforementioned Avamar Hotfix |
https://dl.dell.com/downloads/HW28W_Avamar-19.4-MC-Cumulative-Hotfix-for-Avamar-Server-and-Avamar-Virtual-Edition-November-2022-(Hotfix-337055).zip |
Note:
Customers on 19.3 should upgrade to versions 19.4 or 19.7 and then apply the above hotfix available for your version OR upgrade to 19.8
For IDPA customers “Customers running PowerProtect DP 2.6.0, 2.6.1, 2.7.0, 2.7.1 must upgrade to v2.7.2 first, then apply the AV fix. Customers running PowerProtect DP 2.7.2/2.7.3 can apply the AV fix directly".
| Product | Affected Version | Updated Versions | Update Link |
| Avamar Server, Avamar Virtual Edition | 19.3, 19.4, and 19.7 | 19.8 | https://dl.dell.com/downloads/678J1_Avamar-19.8-for-Server-and-AVE-Upgrades.avp |
| Avamar Server, Avamar Virtual Edition | 19.7 | 19.7 with the latest 19.7 MC Cumulative Hotfix for Avamar Server and Avamar Virtual Edition | Support for Avamar | Drivers & Downloads | Dell US |
| Avamar Server, Avamar Virtual Edition | 19.4 | 19.4 with the latest 19.4 MC Cumulative Hotfix for Avamar Server and Avamar Virtual Edition | Support for Avamar | Drivers & Downloads | Dell US |
| PowerProtect DP Series Appliance (IDPA) |
I2.7.x and 2.6.x | 2.7.2 / 2.7.3 with the aforementioned Avamar Hotfix |
https://dl.dell.com/downloads/HW28W_Avamar-19.4-MC-Cumulative-Hotfix-for-Avamar-Server-and-Avamar-Virtual-Edition-November-2022-(Hotfix-337055).zip |
Note:
Customers on 19.3 should upgrade to versions 19.4 or 19.7 and then apply the above hotfix available for your version OR upgrade to 19.8
For IDPA customers “Customers running PowerProtect DP 2.6.0, 2.6.1, 2.7.0, 2.7.1 must upgrade to v2.7.2 first, then apply the AV fix. Customers running PowerProtect DP 2.7.2/2.7.3 can apply the AV fix directly".
Revision History
| Revision | Date | Description | |
| 1.0 | 2023-02-03 | Initial Release | |
| 2.0 | 2023-03-13 | Updated the "Affected Products" section under "Article Properties" | |
| 3.0 | 2023-04-13 | Updates the "Note" for customers under "Affected Products and Remediation" section |
Related Information
Legal Disclaimer
Affected Products
Avamar, PowerProtect Data Protection Appliance, Avamar, Avamar Client, Avamar Server, Avamar Virtual Edition, PowerProtect Data Protection Software, Integrated Data Protection Appliance Family, PowerProtect Data Protection Hardware
, Integrated Data Protection Appliance Software, Product Security Information
...
Article Properties
Article Number: 000208263
Article Type: Dell Security Advisory
Last Modified: 09 Sept 2025
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.