Critical
Third-party Component | CVEs | More Information |
---|---|---|
Apache Ant | CVE-2020-11979, CVE-2021-36374 | See NVD link below for individual scores for each CVE. https://nvd.nist.gov/ |
Apache Struts | CVE-2023-34149, CVE-2023-34396, CVE-2023-41835, CVE-2023-50164 | See NVD link below for individual scores for each CVE. https://nvd.nist.gov/ |
Jetty: Java based HTTP/1.x, HTTP/2, Servlet, WebSocket Server | CVE-2023-41900 | See NVD link below for individual scores for each CVE. https://nvd.nist.gov/ |
SnakeYAML | CVE-2017-18640 | See NVD link below for individual scores for each CVE. https://nvd.nist.gov/ |
Dozer | CVE-2014-9515 | See NVD link below for individual scores for each CVE. https://nvd.nist.gov/ |
CVEs Addressed |
Product | Software/Firmware | Affected Version(s) | Remediated Version | Link |
---|---|---|---|---|---|
CVE-2020-11979, CVE-2021-36374, CVE-2023-34149, CVE-2023-34396, CVE-2023-41835, CVE-2023-50164, CVE-2023-41900, CVE-2017-18640, CVE-2014-9515 | Dell Avamar Data Store Gen5A, Gen4T | Dell Avamar operating system | Versions 19.4, 19.7,19.8,19.9 and 19.10 | Avamar 19.10 SP1 | https://dl.dell.com/downloads/KYC7K_Avamar-19.10-SP1-for-Server-and-AVE-Upgrades.avp |
CVE-2020-11979, CVE-2021-36374, CVE-2023-34149, CVE-2023-34396, CVE-2023-41835, CVE-2023-50164, CVE-2023-41900, CVE-2017-18640, CVE-2014-9515 | Avamar Virtual Edition for VMware ESXi and vSphere | Dell Avamar operating system | Versions 19.4, 19.7,19.8,19.9 and 19.10 | Avamar 19.10 SP1 | https://dl.dell.com/downloads/NRDN1_Avamar-19.10-SP1-Virtual-Edition-for-VMware-ESXi-and-vSphere.7z |
CVE-2020-11979, CVE-2021-36374, CVE-2023-34149, CVE-2023-34396, CVE-2023-41835, CVE-2023-50164, CVE-2023-41900, CVE-2017-18640, CVE-2014-9515 | Avamar Virtual Edition for VMware vSphere only | Dell Avamar operating system | Versions 19.4, 19.7,19.8,19.9 and 19.10 | Avamar 19.10 SP1 | https://dl.dell.com/downloads/V0RPW_Avamar-19.10-SP1-Virtual-Edition-for-VMware-vSphere-only.ova |
CVE-2020-11979, CVE-2021-36374, CVE-2023-34149, CVE-2023-34396, CVE-2023-41835, CVE-2023-50164, CVE-2023-41900, CVE-2017-18640, CVE-2014-9515 | Avamar Virtual Edition for Hyper-V 2012 | Dell Avamar operating system | Versions 19.4, 19.7,19.8,19.9 and 19.10 | Avamar 19.10 SP1 | https://dl.dell.com/downloads/X59J2_Avamar-19.10-SP1-Virtual-Edition-for-Hyper-V-2012.7z |
CVE-2020-11979, CVE-2021-36374, CVE-2023-34149, CVE-2023-34396, CVE-2023-41835, CVE-2023-50164, CVE-2023-41900, CVE-2017-18640, CVE-2014-9515 | Avamar Virtual Edition for Hyper-V 2012R2, Hyper-V 2016, and Hyper-V 2019 | Dell Avamar operating system | Versions 19.4, 19.7,19.8,19.9 and 19.10 | Avamar 19.10 SP1 | https://dl.dell.com/downloads/163H4_Avamar-19.10-SP1-Virtual-Edition-for-Hyper-V-2012R2,-Hyper-V-2016,-and-Hyper-V-2019.7z |
CVE-2020-11979, CVE-2021-36374, CVE-2023-34149, CVE-2023-34396, CVE-2023-41835, CVE-2023-50164, CVE-2023-41900, CVE-2017-18640, CVE-2014-9515 | Avamar Virtual Edition for KVM/Open Stack KVM | Dell Avamar operating system | Versions 19.4, 19.7,19.8,19.9 and 19.10 | Avamar 19.10 SP1 | https://dl.dell.com/downloads/D3F1V_Avamar-19.10-SP1-Virtual-Edition-for-KVM-OpenStack-KVM.7z |
CVE-2020-11979, CVE-2021-36374, CVE-2023-34149, CVE-2023-34396, CVE-2023-41835, CVE-2023-50164, CVE-2023-41900, CVE-2017-18640, CVE-2014-9515 | Dell PowerProtect DP Series Appliance (Integrated Data Protection Appliance) | Dell Avamar operating system | Versions 2.7.0 through 2.7.6 | Version 2.7.7 | https://dl.dell.com/downloads/NGXWR_PowerProtect-DP-Series-IDPA-2.7.7-Upgrade-for-DP4400-and-DP5900-Appliances.gz |
CVEs Addressed |
Product | Software/Firmware | Affected Version(s) | Remediated Version | Link |
---|---|---|---|---|---|
CVE-2020-11979, CVE-2021-36374, CVE-2023-34149, CVE-2023-34396, CVE-2023-41835, CVE-2023-50164, CVE-2023-41900, CVE-2017-18640, CVE-2014-9515 | Dell Avamar Data Store Gen5A, Gen4T | Dell Avamar operating system | Versions 19.4, 19.7,19.8,19.9 and 19.10 | Avamar 19.10 SP1 | https://dl.dell.com/downloads/KYC7K_Avamar-19.10-SP1-for-Server-and-AVE-Upgrades.avp |
CVE-2020-11979, CVE-2021-36374, CVE-2023-34149, CVE-2023-34396, CVE-2023-41835, CVE-2023-50164, CVE-2023-41900, CVE-2017-18640, CVE-2014-9515 | Avamar Virtual Edition for VMware ESXi and vSphere | Dell Avamar operating system | Versions 19.4, 19.7,19.8,19.9 and 19.10 | Avamar 19.10 SP1 | https://dl.dell.com/downloads/NRDN1_Avamar-19.10-SP1-Virtual-Edition-for-VMware-ESXi-and-vSphere.7z |
CVE-2020-11979, CVE-2021-36374, CVE-2023-34149, CVE-2023-34396, CVE-2023-41835, CVE-2023-50164, CVE-2023-41900, CVE-2017-18640, CVE-2014-9515 | Avamar Virtual Edition for VMware vSphere only | Dell Avamar operating system | Versions 19.4, 19.7,19.8,19.9 and 19.10 | Avamar 19.10 SP1 | https://dl.dell.com/downloads/V0RPW_Avamar-19.10-SP1-Virtual-Edition-for-VMware-vSphere-only.ova |
CVE-2020-11979, CVE-2021-36374, CVE-2023-34149, CVE-2023-34396, CVE-2023-41835, CVE-2023-50164, CVE-2023-41900, CVE-2017-18640, CVE-2014-9515 | Avamar Virtual Edition for Hyper-V 2012 | Dell Avamar operating system | Versions 19.4, 19.7,19.8,19.9 and 19.10 | Avamar 19.10 SP1 | https://dl.dell.com/downloads/X59J2_Avamar-19.10-SP1-Virtual-Edition-for-Hyper-V-2012.7z |
CVE-2020-11979, CVE-2021-36374, CVE-2023-34149, CVE-2023-34396, CVE-2023-41835, CVE-2023-50164, CVE-2023-41900, CVE-2017-18640, CVE-2014-9515 | Avamar Virtual Edition for Hyper-V 2012R2, Hyper-V 2016, and Hyper-V 2019 | Dell Avamar operating system | Versions 19.4, 19.7,19.8,19.9 and 19.10 | Avamar 19.10 SP1 | https://dl.dell.com/downloads/163H4_Avamar-19.10-SP1-Virtual-Edition-for-Hyper-V-2012R2,-Hyper-V-2016,-and-Hyper-V-2019.7z |
CVE-2020-11979, CVE-2021-36374, CVE-2023-34149, CVE-2023-34396, CVE-2023-41835, CVE-2023-50164, CVE-2023-41900, CVE-2017-18640, CVE-2014-9515 | Avamar Virtual Edition for KVM/Open Stack KVM | Dell Avamar operating system | Versions 19.4, 19.7,19.8,19.9 and 19.10 | Avamar 19.10 SP1 | https://dl.dell.com/downloads/D3F1V_Avamar-19.10-SP1-Virtual-Edition-for-KVM-OpenStack-KVM.7z |
CVE-2020-11979, CVE-2021-36374, CVE-2023-34149, CVE-2023-34396, CVE-2023-41835, CVE-2023-50164, CVE-2023-41900, CVE-2017-18640, CVE-2014-9515 | Dell PowerProtect DP Series Appliance (Integrated Data Protection Appliance) | Dell Avamar operating system | Versions 2.7.0 through 2.7.6 | Version 2.7.7 | https://dl.dell.com/downloads/NGXWR_PowerProtect-DP-Series-IDPA-2.7.7-Upgrade-for-DP4400-and-DP5900-Appliances.gz |
Revision | Date | Description |
---|---|---|
1.0 | 2024-06-26 | Initial Release |
2.0 | 2024-08-20 | Updated Advisory stating that version 19.10 SP1 will address issues related to the proxy, AVE, and ADS. |
3.0 | 2024-08-28 | Updated Advisory as IDPA has announced the release of Version 2.7.7, which includes fixes for the disclosed vulnerability |
4.0 | 2025-02-24 | Updated the advisory with Third-Party component details for CVE-2014-9515 |