DSA-2023-172: Security Update for Dell Networker Apache Tomcat Vulnerabilities
Resumen: Dell NetWorker remediation is available for Apache Tomcat vulnerabilities that could be exploited by malicious users to compromise the affected system
Este artículo se aplica a:
Este artículo no se aplica a:
Este artículo no está vinculado a ningún producto específico.
En este artículo no se identifican todas las versiones de los productos.
Impacto
High
Detalles
| Third-party Component | CVEs | More Information |
|---|---|---|
| Apache Tomcat | CVE-2023-24998 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
Productos afectados y corrección
| CVEs Addressed | Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
|---|---|---|---|---|---|
| CVE-2023-24998 | NetWorker | NetWorker Authentication Service, NetWorker Server | Versions 19.9 | Versions 19.9.0.1 & later releases, Version 19.7.0.5 | https://www.dell.com/support/home/product-support/product/networker/drivers |
| CVE-2023-24998 | NetWorker | NetWorker Authentication Service, NetWorker Server | Versions 19.8 through 19.8.0.2 | Versions 19.9.0.1 & later releases, Version 19.7.0.5 | https://www.dell.com/support/home/product-support/product/networker/drivers |
| CVE-2023-24998 | NetWorker | NetWorker Authentication Service, NetWorker Server | Versions 19.7 through 19.7.0.4 | Versions 19.9.0.1 & later releases, Version 19.7.0.5 | https://www.dell.com/support/home/product-support/product/networker/drivers |
| CVE-2023-24998 | NetWorker | NetWorker Authentication Service, NetWorker Server | Versions 19.7.1 | Versions 19.9.0.1 & later releases, Version 19.7.0.5 | https://www.dell.com/support/home/product-support/product/networker/drivers |
| CVE-2023-24998 | NetWorker | NetWorker Authentication Service, NetWorker Server | Versions prior to 19.7 | Versions 19.9.0.1 & later releases, Version 19.7.0.5 | https://www.dell.com/support/home/product-support/product/networker/drivers |
| CVEs Addressed | Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
|---|---|---|---|---|---|
| CVE-2023-24998 | NetWorker | NetWorker Authentication Service, NetWorker Server | Versions 19.9 | Versions 19.9.0.1 & later releases, Version 19.7.0.5 | https://www.dell.com/support/home/product-support/product/networker/drivers |
| CVE-2023-24998 | NetWorker | NetWorker Authentication Service, NetWorker Server | Versions 19.8 through 19.8.0.2 | Versions 19.9.0.1 & later releases, Version 19.7.0.5 | https://www.dell.com/support/home/product-support/product/networker/drivers |
| CVE-2023-24998 | NetWorker | NetWorker Authentication Service, NetWorker Server | Versions 19.7 through 19.7.0.4 | Versions 19.9.0.1 & later releases, Version 19.7.0.5 | https://www.dell.com/support/home/product-support/product/networker/drivers |
| CVE-2023-24998 | NetWorker | NetWorker Authentication Service, NetWorker Server | Versions 19.7.1 | Versions 19.9.0.1 & later releases, Version 19.7.0.5 | https://www.dell.com/support/home/product-support/product/networker/drivers |
| CVE-2023-24998 | NetWorker | NetWorker Authentication Service, NetWorker Server | Versions prior to 19.7 | Versions 19.9.0.1 & later releases, Version 19.7.0.5 | https://www.dell.com/support/home/product-support/product/networker/drivers |
The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
- Platforms: Windows & Linux (All variants and flavors are impacted)
- We plan to release a remediation fix for this issue in 19.8.x in the near future.
- Versions prior to 19.7 means versions 19.6.x, 19.5.x, 19.4.x family of releases that are still under standard support. For more information on Dell End-of-Life Documents for converged infrastructure, midrange and enterprise storage, and storage networking products kindly refer to: https://www.dell.com/support/kbdoc/000185734/all-dell-emc-end-of-life-documents?lang=en
- The term “later releases” encompasses all NetWorker releases, under standard support, that are of a higher minor or major version than the specified release.”
Historial de revisiones
| Revision | Date | Description |
| 1.0 | 2023-07-03 | Initial Release |
| 2.0 | 2023-07-05 | Updated for enhanced presentation with no change to content |
| 3.0 | 2023-08-02 |
|
| 4.0 | 2023-08-03 | Updated for enhanced format presentation with no change to content |
| 5.0 | 2023-08-08 | Clarified which NetWorker components were affected. Clarified the affected version and added remediated versions 19.7.0.5. Added more details in "Additional Information" section. |
| 6.0 | 2023-08-10 | Clarified and added "Later Releases" details under point 4 in "Additional Information" section. |
Información relacionada
Aviso legal
Productos afectados
NetWorker Family, NetWorker, NetWorker Series, NetWorker Module, Product Security InformationPropiedades del artículo
Número de artículo: 000215494
Tipo de artículo: Dell Security Advisory
Última modificación: 09 sept 2025
Encuentra las respuestas que necesitas con la ayuda de otros usuarios de Dell
Servicios de asistencia
Comprueba si tu dispositivo está cubierto por los servicios de asistencia.