VPLEX: Metro Node False Positive Security Vulnerabilities

Resumen: This article provides a list of security vulnerabilities that cannot be exploited on Dell VPLEX GeoSynchrony 6.x SuSE Linux Enterprise Server (SLES) OS but which may be identified by security scanners. ...

Este artículo se aplica a Este artículo no se aplica a Este artículo no está vinculado a ningún producto específico. No se identifican todas las versiones del producto en este artículo.

Tipo de artículo de seguridad

Security KB

Identificador de CVE

The CVE IDs are listed in the table below.

Resumen del problema

See the 'Recommendation' section below for details on each CVE.

Recomendaciones

The vulnerabilities listed in the table below are in order by the date on which VPLEX/Metro Node Engineering determined that the VPLEX GeoSynchrony and Metro Node OS SLES are not vulnerable.
 
Embedded Component CVE ID Summary of Vulnerability Reason why Product is not Vulnerable Date Determined False Positive
Spring4Shell CVE-2022-22963 In Spring Cloud Function versions 3.1.6, 3.2.2, and earlier unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources. SUSE does not include the Spring framework in its products, so none of our products are affected by this issue.

SUSE Bugzilla entry: 1197804 [RESOLVED / INVALID]
January 10,  2022
Spring4Shell CVE-2022-22965 A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) using data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, (the default), it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it. SUSE does not include the Spring framework in its products, so none of our products are affected by this issue.

SUSE Bugzilla entry: 1197879 [RESOLVED / INVALID]
January 10, 2022

Información adicional

Productos afectados

metro node mn-114, VPLEX Series, VPLEX VS2, VPLEX VS6
Propiedades del artículo
Número del artículo: 000198111
Tipo de artículo: Security KB
Última modificación: 13 may 2026
Versión:  3
Encuentre respuestas a sus preguntas de otros usuarios de Dell
Servicios de soporte
Compruebe si el dispositivo está cubierto por los servicios de soporte.