DSA-2021-297: Dell EMC Streaming Data Platform Security Update for Apache Log4j Remote Code Execution Vulnerability
Yhteenveto: Dell EMC Streaming Data Platform remediation is available for the Apache Log4j Remote Code Execution Vulnerability that may be exploited by malicious users to compromise the affected system. Dell recommends implementing this remediation as soon as possible in light of the critical severity of the vulnerability. ...
Tämä artikkeli koskee tuotetta
Tämä artikkeli ei koske tuotetta
Tämä artikkeli ei liity tiettyyn tuotteeseen.
Tässä artikkelissa ei yksilöidä kaikkia tuoteversioita.
Vaikutus
Critical
Tiedot
| Third-Party Component | CVEs | More information |
| Apache Log4j | CVE-2021-44228 | Apache Log4j Remote Code Execution |
| CVE-2021-45046 | ||
| CVE-2021-45105 | ||
| CVE-2021-44832 |
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.
| Third-Party Component | CVEs | More information |
| Apache Log4j | CVE-2021-44228 | Apache Log4j Remote Code Execution |
| CVE-2021-45046 | ||
| CVE-2021-45105 | ||
| CVE-2021-44832 |
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.
Tuotteet, joihin asia vaikuttaa, ja tilanteen korjaaminen
|
Note: Dell EMC Streaming Data Platform (SDP) has remediated CVE-2021-44228, CVE-2021-45046 in version 1.3.1 and later. Although CVE-2021-45105, CVE-2021-44832 were not exploitable in SDP, Apache Log4j is upgraded to 2.17.1 in SDP 1.3.1.1
|
Note: Dell EMC Streaming Data Platform (SDP) has remediated CVE-2021-44228, CVE-2021-45046 in version 1.3.1 and later. Although CVE-2021-45105, CVE-2021-44832 were not exploitable in SDP, Apache Log4j is upgraded to 2.17.1 in SDP 1.3.1.1
Versiohistoria
| Revision | Date | Description |
| 1.0 | 2021-12-16 | Initial Release |
| 1.1 | 2021-12-17 | Updated the SDP 1.3.1 download link |
| 1.2 | 2022-01-19 | Added version 1.3.1.1 and additional CVE-2021-45105, CVE-2021-44832 |
Asiaan liittyvät tiedot
Vastuuvapauslauseke
Tuotteet, joihin vaikutus kohdistuu
Streaming Data PlatformTuotteet
Streaming Data Platform FamilyArtikkelin ominaisuudet
Artikkelin numero: 000194627
Artikkelin tyyppi: Dell Security Advisory
Viimeksi muutettu: 05 marrask. 2025
Etsi vastauksia kysymyksiisi muilta Dell-käyttäjiltä
Tukipalvelut
Tarkista, kuuluuko laitteesi tukipalveluiden piiriin.