Dell EMC OpenManage Plug-in for Nagios Core False Positive Security Vulnerability

Riepilogo: This article provides a list of security vulnerabilities that cannot be exploited on Dell EMC OpenManage Plug-in for Nagios Core version 3.1 and earlier, but which may be identified by security scanners. ...

Questo articolo si applica a Questo articolo non si applica a Questo articolo non è legato a un prodotto specifico. Non tutte le versioni del prodotto sono identificate in questo articolo.

Tipo di articolo sulla sicurezza

Security KB

ID CVE

The CVE IDs are listed in the table below.

Riepilogo del problema

See the 'Recommendation' section below for details on each CVE.

Raccomandazioni

The vulnerabilities that are listed in the below table are in order by the date on which Dell EMC OpenManage Plug-in for Nagios Core Engineering determined that the Dell EMC OpenManage Plug-in for Nagios Core version 3.1 and earlier are not vulnerable.
 
Third-party  Component CVE IDs Summary of Vulnerability Reason why Product is not Vulnerable Date Determined False Positive
Apache Log4j 1.2.17-cloudera1 CVE-2021-4104  Requires use of JMSAppender, a nonstandard configuration Does not use JMSAppender configuration December 20, 2021
Apache Log4j 1.2.17-cloudera1 CVE-2019-17571  Requires use of SocketServer, a nonstandard configuration Does not use SocketServer configuration December 20, 2021
Apache Log4j 1.2.17-cloudera1 CVE-2022-23302 Requires use of JMSAppender, a nonstandard configuration Does not use JMSAppender configuration March 11, 2022
Apache Log4j 1.2.17-cloudera1 CVE-2022-23305 Requires use of JDBCAppender, a nonstandard configuration Does not use JDBCAppender configuration March 11, 2022
Apache Log4j 1.2.17-cloudera1 CVE-2022-23307 Requires use of Chainsaw, a nonstandard configuration Does not use Chainsaw configuration March 11, 2022

Prodotti interessati

Dell OpenManage Plug-in for Nagios Core, Dell OpenManage Plug-in for Nagios Core version 2.0, Dell OpenManage Plug-in for Nagios Core version 1.0, Dell EMC OpenManage Plug-in for Nagios Core - Current Version , Dell OpenManage Plug-in for Nagios Core version 2.1, Dell EMC OpenManage Plug-in v3.0 for Nagios Core, Product Security Information ...
Proprietà dell'articolo
Numero articolo: 000195050
Tipo di articolo: Security KB
Ultima modifica: 01 apr 2022
Versione:  2
Trova risposta alle tue domande dagli altri utenti Dell
Support Services
Verifica che il dispositivo sia coperto dai Servizi di supporto.