DSA-2021-270: Enterprise Hybrid Cloud Security Update for Apache Log4j Remote Code Execution Vulnerability (CVE-2021-44228)

Yhteenveto: Enterprise Hybrid Cloud remediation is available for the Apache Log4j Remote Code Execution Vulnerability that may be exploited by malicious users to compromise the affected system. Dell recommends implementing this remediation as soon as possible in light of the critical severity of the vulnerability. ...

Tämä artikkeli koskee tuotetta Tämä artikkeli ei koske tuotetta Tämä artikkeli ei liity tiettyyn tuotteeseen. Tässä artikkelissa ei yksilöidä kaikkia tuoteversioita.

Vaikutus

Critical

Tiedot

Third-party Component CVE More information
Apache log4j CVE-2021-44228 Apache Log4j Remote Code Execution
DSN-2021-007: Dell Response to Apache Log4j Remote Code Execution Vulnerability 
Third-party Component CVE More information
Apache log4j CVE-2021-44228 Apache Log4j Remote Code Execution
DSN-2021-007: Dell Response to Apache Log4j Remote Code Execution Vulnerability 
Dell Technologies suosittelee, että kaikki asiakkaat ottavat huomioon sekä CVSS-peruspistemäärän että kaikki asiaankuuluvat väliaikaiset ja ympäristöön liittyvät pisteet, jotka voivat vaikuttaa tietyn tietoturvahaavoittuvuuden mahdolliseen vakavuuteen.

Tuotteet, joihin asia vaikuttaa, ja tilanteen korjaaminen

Enterprise Hybrid Cloud 4.1.2 workflows is not impacted by this advisory, including packages Update 1 through 8.

Monitor the following advisories and apply workaround guidance and remediations as they become available:
 
CVE Addressed Products Link to Update
CVE-2021-44228 VMware vCenter Server Appliance VMSA-2021-0028.3
VMware vRealize Automation 7.x
VMware vRealize Orchestrator 7.x
VMware NSX for Data Center for vSphere 6.x
VMware vRealize Log Insight 8.x
VMware vRealize Business for Cloud 7.x
Dell EMC Data Domain OS DSA-2021-274
 
Dell EMC Avamar DSA-2021-277
Dell EMC VxRail DSA-2021-265
VxBlock See vce6771 (requires customer login)
Dell EMC Unity Monitor Knowledge Baste Article 194414 for advisory publication: https://www.dell.com/support/kbdoc/en-uk/000194414/dell-response-to-apache-log4j-remote-code-execution-vulnerability
Dell EMC RecoverPoint for Virtual Machines DSA-2021-284

 Note: Dell EMC RecoverPoint for Virtual Machines plugin is not impacted by this advisory, all packages Update 1 through 8 are covered.
Enterprise Hybrid Cloud 4.1.2 workflows is not impacted by this advisory, including packages Update 1 through 8.

Monitor the following advisories and apply workaround guidance and remediations as they become available:
 
CVE Addressed Products Link to Update
CVE-2021-44228 VMware vCenter Server Appliance VMSA-2021-0028.3
VMware vRealize Automation 7.x
VMware vRealize Orchestrator 7.x
VMware NSX for Data Center for vSphere 6.x
VMware vRealize Log Insight 8.x
VMware vRealize Business for Cloud 7.x
Dell EMC Data Domain OS DSA-2021-274
 
Dell EMC Avamar DSA-2021-277
Dell EMC VxRail DSA-2021-265
VxBlock See vce6771 (requires customer login)
Dell EMC Unity Monitor Knowledge Baste Article 194414 for advisory publication: https://www.dell.com/support/kbdoc/en-uk/000194414/dell-response-to-apache-log4j-remote-code-execution-vulnerability
Dell EMC RecoverPoint for Virtual Machines DSA-2021-284

 Note: Dell EMC RecoverPoint for Virtual Machines plugin is not impacted by this advisory, all packages Update 1 through 8 are covered.

Kiertotavat ja lievennyskeinot

Follow workaround and mitigation information in articles and advisories linked in the Affected Products and Remediation section.

Versiohistoria

RevisionDateDescription
1.02021-12-14Initial Release
1.12021-12-17Updated Content

Asiaan liittyvät tiedot

Tuotteet, joihin vaikutus kohdistuu

Enterprise Hybrid Cloud, Enterprise Hybrid Cloud

Tuotteet

Product Security Information
Artikkelin ominaisuudet
Artikkelin numero: 000194490
Artikkelin tyyppi: Dell Security Advisory
Viimeksi muutettu: 12 toukok. 2026
Etsi vastauksia kysymyksiisi muilta Dell-käyttäjiltä
Tukipalvelut
Tarkista, kuuluuko laitteesi tukipalveluiden piiriin.