DSA-2021-274: Dell EMC Data Domain Security Update for Apache Log4j Remote Code Execution Vulnerability (CVE-2021-44228 and CVE-2021-45046)
Summary: Dell EMC Data Domain workaround and mitigation is available before remediation for the Apache Log4j Remote Code Execution Vulnerability that may be exploited by malicious users to compromise the affected system. Dell recommends implementing this remediation as soon as possible in light of the critical severity of the vulnerability. ...
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Impact
Critical
Details
| Third-party Component | CVEs | More information |
| Apache Log4J | CVE-2021-44228 | Apache Log4j Remote Code Execution |
| CVE-2021-45046 | Apache Log4j Remote Code Execution |
| Third-party Component | CVEs | More information |
| Apache Log4J | CVE-2021-44228 | Apache Log4j Remote Code Execution |
| CVE-2021-45046 | Apache Log4j Remote Code Execution |
Affected Products & Remediation
|
|
Workarounds & Mitigations
Disable UI using command "adminaccess disable HTTP" and "adminaccess disable HTTPS"
See Dell KB article 126375: PowerProtect and Data Domain core documents to view the Dell EMC DD OS Command Reference Guide for details.
Revision History
| Revision | Date | Description |
| 1.0 | 2021-12-15 | Initial Release |
| 1.1 | 2021-12-17 | Update released |
| 1.2 | 2021-12-29 | updated versions and workaround section |
| 1.3 | 2022-01-04 | Added not impacted products |
| 1.4 | 2022-01-28 | Added updated version 7.7.1.0 |
| 1.5 | 2022-04-20 | Updated Affected Products table |
Related Information
Legal Disclaimer
Affected Products
Data Domain, Data Domain, Product Security InformationArticle Properties
Article Number: 000194503
Article Type: Dell Security Advisory
Last Modified: 19 Sep 2025
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.