DSA-2020-070: Dell Wyse Management Suite and Dell Wyse Management Repository Security Update for Apache Tomcat Vulnerability
Summary: The Apache Tomcat component within Dell Wyse Management Suite and Dell Wyse Management Repository requires a mitigation to address a vulnerability.
Impact
Critical
Details
The component below is updated for the following vulnerability:
- Apache Tomcat
CVE-2020-1938
For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm. To search for a particular CVE, use the database’s search utility at http://web.nvd.nist.gov/view/vuln/search.
The component below is updated for the following vulnerability:
- Apache Tomcat
CVE-2020-1938
For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm. To search for a particular CVE, use the database’s search utility at http://web.nvd.nist.gov/view/vuln/search.
Affected Products & Remediation
Affected products:
Dell Wyse Management Suite versions prior to 2.0
Dell Wyse Management Repository versions prior to 2.0
Remediation:
The following Dell Wyse Management Suite and Dell Wyse Management Repository releases contains a mitigation to this vulnerability:
- Dell Wyse Management Suite 2.0 or later
- Dell Wyse Management Repository 2.0 or later
Note: The Dell Wyse Management Remote Repository option is only available with the pro license of Dell Wyse Management Suite. If you have Dell Wyse Management Suite Pro, the remote repository install binaries can be downloaded from Dell Digital Locker, which is where the pro licenses are registered.
Workaround:
Customers can either upgrade to 2.0 or later or choose to apply the workaround listed below to mitigate this vulnerability for existing Dell Wyse Management Suite and Dell Wyse Management Repository releases 1.4.1, 1.4 and 1.3.
- Identifying the Tomcat installation directory
- Open the window service panel using "services.msc" command in command prompt.
- Search "Dell WMS: Tomcat Service" service from the service panel.
- Open the properties of the searched services.
- Excluding "bin/Tomcat9.exe" from the "Path to executable" property of the above located service will be the path of Tomcat installation.
- This obtained value from step (d) will be considered as <CATALINA_BASE> in the steps listed below.
- Configuration changes
- Edit <CATALINA_BASE>/conf/server.xml and locate the following line: (<CATALINA_BASE> is the Tomcat work directory): <Connector port="8009" protocol="AJP/1.3" redirectPort="8443" />
- Comment out (or just delete it): <!--<Connector port="8009" protocol="AJP/1.3" redirectPort="8443" />-->
- Save the edit.
- Restart Tomcat.
Affected products:
Dell Wyse Management Suite versions prior to 2.0
Dell Wyse Management Repository versions prior to 2.0
Remediation:
The following Dell Wyse Management Suite and Dell Wyse Management Repository releases contains a mitigation to this vulnerability:
- Dell Wyse Management Suite 2.0 or later
- Dell Wyse Management Repository 2.0 or later
Note: The Dell Wyse Management Remote Repository option is only available with the pro license of Dell Wyse Management Suite. If you have Dell Wyse Management Suite Pro, the remote repository install binaries can be downloaded from Dell Digital Locker, which is where the pro licenses are registered.
Workaround:
Customers can either upgrade to 2.0 or later or choose to apply the workaround listed below to mitigate this vulnerability for existing Dell Wyse Management Suite and Dell Wyse Management Repository releases 1.4.1, 1.4 and 1.3.
- Identifying the Tomcat installation directory
- Open the window service panel using "services.msc" command in command prompt.
- Search "Dell WMS: Tomcat Service" service from the service panel.
- Open the properties of the searched services.
- Excluding "bin/Tomcat9.exe" from the "Path to executable" property of the above located service will be the path of Tomcat installation.
- This obtained value from step (d) will be considered as <CATALINA_BASE> in the steps listed below.
- Configuration changes
- Edit <CATALINA_BASE>/conf/server.xml and locate the following line: (<CATALINA_BASE> is the Tomcat work directory): <Connector port="8009" protocol="AJP/1.3" redirectPort="8443" />
- Comment out (or just delete it): <!--<Connector port="8009" protocol="AJP/1.3" redirectPort="8443" />-->
- Save the edit.
- Restart Tomcat.