DSA-2020-219: Dell EMC Avamar and NetWorker Security Update for Multiple Third Party Component Vulnerabilities
Summary: Dell EMC Avamar and Dell EMC NetWorker remediation available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
Critical
Details
The 2020 R3 OS Security Update addresses multiple third-party components within the listed Dell EMC Avamar and NetWorker products that require a security update to address various vulnerabilities. This is a cumulative update that includes vulnerabilities addressed in previous updates as well as new vulnerabilities.
Note:
The CVEs remedied by this security update are listed in the Release Notes. The Release Notes list not only the new CVEs remedied by this update but all the past CVEs included in this cumulative update.
For Dell EMC Avamar servers running SUSE Linux Enterprise 11 SP1 / SP3, where the OS versions are end of life, the security update only addresses CVEs which SUSE has provided updates for and also updates some third party packages, such as JRE and Tomcat. It is recommended to upgrade Avamar servers to SUSE Linux Enterprise 11 SP4 prior to applying the OS Security Update.
This security patch is a set of security updates for various third-party software components installed on the Avamar and NetWorker nodes. The patch addresses multiple security vulnerabilities in those components. The patch applies to all Avamar and NetWorker products running on the SLES platforms listed above. The products include Avamar single-node servers, multi-node servers, accelerator nodes, Avamar Virtual Edition systems, NetWorker Virtual Edition systems, Avamar Combined Proxy, and Avamar Plug-in for vCloud Director.
This security patch also updates Java JRE to version 8u261 for Avamar Server 7.5.1 and later, Avamar Proxy 7.5.1 and later, NetWorker Virtual Edition 18.x and later, and Dell EMC Avamar NDMP Accelerator 7.5.1 and later.
This security patch also updates Apache Tomcat to version 8.5.57 for Avamar Server 7.5.1 and later.
This security patch is a set of security updates for various third-party software components installed on the Avamar and NetWorker nodes. The patch addresses multiple security vulnerabilities in those components. The patch applies to all Avamar and NetWorker products running on the SLES platforms listed above. The products include Avamar single-node servers, multi-node servers, accelerator nodes, Avamar Virtual Edition systems, NetWorker Virtual Edition systems, Avamar Combined Proxy, and Avamar Plug-in for vCloud Director.
This security patch also updates Java JRE to version 8u261 for Avamar Server 7.5.1 and later, Avamar Proxy 7.5.1 and later, NetWorker Virtual Edition 18.x and later, and Dell EMC Avamar NDMP Accelerator 7.5.1 and later.
This security patch also updates Apache Tomcat to version 8.5.57 for Avamar Server 7.5.1 and later.
Affected Products & Remediation
Affected products:
-
Dell EMC Avamar Server hardware appliance Gen4S with versions 7.5.1 and later running SUSE Linux Enterprise 11 SP1
-
Dell EMC Avamar Server hardware appliance Gen4T with versions 7.5.1 and later running SUSE Linux Enterprise 11 SP3
-
Dell EMC Avamar Server hardware appliance Gen4S / Gen4T with versions 7.5.1 and later running SUSE Linux Enterprise 11 SP4
-
Dell EMC Avamar Server hardware appliance Gen4S / Gen4T with versions 19.2 running SUSE Linux Enterprise 12 SP4
-
Dell EMC Avamar Server hardware appliance Gen4S / Gen4T with versions 19.3 running SUSE Linux Enterprise 12 SP5
-
Dell EMC Avamar Virtual Edition versions 7.5.1 and later running SUSE Linux Enterprise 11 SP3
-
Dell EMC Avamar Virtual Edition versions 7.5.1 and later running SUSE Linux Enterprise 11 SP4 (including Azure and AWS deployments)
-
Dell EMC Avamar Virtual Edition versions 19.2 running SUSE Linux Enterprise 12 SP4 (including Azure and AWS deployments)
-
Dell EMC Avamar Virtual Edition versions 19.3 running SUSE Linux Enterprise 12 SP5 (including Azure and AWS deployments)
-
Dell EMC Avamar NDMP Accelerator 7.5.1 and later running SUSE Linux Enterprise 11 SP1 / SP3 or SUSE Linux Enterprise 12 SP4 / SP5
-
Dell EMC Avamar VMware Image Proxy versions 7.5.1 and later running SUSE Linux Enterprise 12 SP1 / SP4
-
Dell EMC NetWorker Virtual Edition (NVE) versions 18.x and later running SUSE Linux Enterprise 11 SP3 / SP4
-
Dell EMC vCloud Director Data Protection Extension versions 2.0.6 and later running SUSE Linux Enterprise 11 SP3
-
Dell EMC Integrated Data Protection Appliance (IDPA) 2.2, 2.3, 2.4, and 2.5.
Remediation:
Apply the platform security patch to Avamar software version and NetWorker Virtual Edition (NVE). The following platform security patch packages are now available to be installed:
- SLES11 SP1/SP3/SP4, SLES12 SP4/SP5 Avamar: AvPlatformOsRollup_2020-R3.avp
- SLES11 SP3/SP4 NVE: NvePlatformOsRollup_2020-R3.avp
- Avamar Proxy Bundle 2020-R3.tgz
The Security Update for Avamar Virtual Edition and NetWorker Virtual Edition is customer installable. Refer to download and installation instructions below.
The installation process involves shutting down the server software, rebooting all the nodes, and restarting the server software, and so appropriate time needs to be scheduled and allocated to perform this full process.
Dell EMC strongly recommends all customers upgrade at the earliest opportunity.
To schedule platform security patch installation, or to upgrade your server, contact Dell EMC Customer Support at https://support.emc.com/.
Refer to the following KB articles for Security Update (Rollup) Installation instructions:
-
Avamar Virtual Edition: KB 335359: Avamar Virtual Edition, NetWorker Virtual Appliance: How to Install the Avamar Platform Security Rollup (Only registered Dell Customers can access the content on the article link via Dell.com/support)
-
NetWorker Virtual Edition: KB 476507: NetWorker Virtual Edition (NVE) : How to Install the Platform Security Rollup
-
Avamar Platform Security Rollup on the Avamar Proxy: KB 335361: Avamar Proxy, Avamar Server: How to install the Avamar Platform Security Rollup with command line (Only registered Dell Customers can access the content on the article link via Dell.com/support)
Read more in the Release Notes:
Affected products:
-
Dell EMC Avamar Server hardware appliance Gen4S with versions 7.5.1 and later running SUSE Linux Enterprise 11 SP1
-
Dell EMC Avamar Server hardware appliance Gen4T with versions 7.5.1 and later running SUSE Linux Enterprise 11 SP3
-
Dell EMC Avamar Server hardware appliance Gen4S / Gen4T with versions 7.5.1 and later running SUSE Linux Enterprise 11 SP4
-
Dell EMC Avamar Server hardware appliance Gen4S / Gen4T with versions 19.2 running SUSE Linux Enterprise 12 SP4
-
Dell EMC Avamar Server hardware appliance Gen4S / Gen4T with versions 19.3 running SUSE Linux Enterprise 12 SP5
-
Dell EMC Avamar Virtual Edition versions 7.5.1 and later running SUSE Linux Enterprise 11 SP3
-
Dell EMC Avamar Virtual Edition versions 7.5.1 and later running SUSE Linux Enterprise 11 SP4 (including Azure and AWS deployments)
-
Dell EMC Avamar Virtual Edition versions 19.2 running SUSE Linux Enterprise 12 SP4 (including Azure and AWS deployments)
-
Dell EMC Avamar Virtual Edition versions 19.3 running SUSE Linux Enterprise 12 SP5 (including Azure and AWS deployments)
-
Dell EMC Avamar NDMP Accelerator 7.5.1 and later running SUSE Linux Enterprise 11 SP1 / SP3 or SUSE Linux Enterprise 12 SP4 / SP5
-
Dell EMC Avamar VMware Image Proxy versions 7.5.1 and later running SUSE Linux Enterprise 12 SP1 / SP4
-
Dell EMC NetWorker Virtual Edition (NVE) versions 18.x and later running SUSE Linux Enterprise 11 SP3 / SP4
-
Dell EMC vCloud Director Data Protection Extension versions 2.0.6 and later running SUSE Linux Enterprise 11 SP3
-
Dell EMC Integrated Data Protection Appliance (IDPA) 2.2, 2.3, 2.4, and 2.5.
Remediation:
Apply the platform security patch to Avamar software version and NetWorker Virtual Edition (NVE). The following platform security patch packages are now available to be installed:
- SLES11 SP1/SP3/SP4, SLES12 SP4/SP5 Avamar: AvPlatformOsRollup_2020-R3.avp
- SLES11 SP3/SP4 NVE: NvePlatformOsRollup_2020-R3.avp
- Avamar Proxy Bundle 2020-R3.tgz
The Security Update for Avamar Virtual Edition and NetWorker Virtual Edition is customer installable. Refer to download and installation instructions below.
The installation process involves shutting down the server software, rebooting all the nodes, and restarting the server software, and so appropriate time needs to be scheduled and allocated to perform this full process.
Dell EMC strongly recommends all customers upgrade at the earliest opportunity.
To schedule platform security patch installation, or to upgrade your server, contact Dell EMC Customer Support at https://support.emc.com/.
Refer to the following KB articles for Security Update (Rollup) Installation instructions:
-
Avamar Virtual Edition: KB 335359: Avamar Virtual Edition, NetWorker Virtual Appliance: How to Install the Avamar Platform Security Rollup (Only registered Dell Customers can access the content on the article link via Dell.com/support)
-
NetWorker Virtual Edition: KB 476507: NetWorker Virtual Edition (NVE) : How to Install the Platform Security Rollup
-
Avamar Platform Security Rollup on the Avamar Proxy: KB 335361: Avamar Proxy, Avamar Server: How to install the Avamar Platform Security Rollup with command line (Only registered Dell Customers can access the content on the article link via Dell.com/support)
Read more in the Release Notes:
Workarounds & Mitigations
None.
Revision History
| Revision | Date | Description |
| 1.0 | 22/05/2021 | Initial Release |
| 1.1 | 03/11/2021 | Updated Product Tagging |