DSA-2025-138: Security Update for Dell Data Protection Central for Third-Party Component Vulnerabilities
Summary: Dell Data Protection Central remediation is available for multiple third-party vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
Critical
Additional Details
This Security Advisory applies to Data Protection Central, Versions prior 19.9.0 through 19.11.0-2.
Details
|
Third-party Component |
CVEs |
More Information |
|---|---|---|
|
Keycloak |
CVE-2024-3656, CVE-2024-1132, CVE-2024-4540, CVE-2024-1249, CVE-2024-2419, CVE-2024-2700, CVE-2024-8698, CVE-2024-47554, CVE-2024-7341, CVE-2024-8883 |
|
|
Iam |
CVE-2024-37370, CVE-2024-21147, CVE-2023-52428 |
|
|
Postgres |
CVE-2024-25062 |
|
|
Akk-actoer |
CVE-2023-31442 |
|
|
Elliptic |
CVE-2024-42461 |
|
|
Socket.IO Parser |
CVE-2023-32695 |
Affected Products & Remediation
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Link |
|---|---|---|---|---|
|
Data Protection Central |
DPC_19.12 |
Versions 19.9.0 through 19.11.0-2 |
Version 19.12.0-2 or later |
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Link |
|---|---|---|---|---|
|
Data Protection Central |
DPC_19.12 |
Versions 19.9.0 through 19.11.0-2 |
Version 19.12.0-2 or later |
Note:
- Platform: SUSE Linux Enterprise Server 12 SP5
- See the latest Dell Data Protection Central 19.12 Release Notes
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2025-03-20 |
Initial Release |