DSA-2021-270: Enterprise Hybrid Cloud Security Update for Apache Log4j Remote Code Execution Vulnerability (CVE-2021-44228)
概要: Enterprise Hybrid Cloud remediation is available for the Apache Log4j Remote Code Execution Vulnerability that may be exploited by malicious users to compromise the affected system. Dell recommends implementing this remediation as soon as possible in light of the critical severity of the vulnerability. ...
この記事は次に適用されます:
この記事は次には適用されません:
この記事は、特定の製品に関連付けられていません。
すべての製品パージョンがこの記事に記載されているわけではありません。
影響
Critical
詳細
| Third-party Component | CVE | More information |
| Apache log4j | CVE-2021-44228 | Apache Log4j Remote Code Execution
DSN-2021-007: Dell Response to Apache Log4j Remote Code Execution Vulnerability |
| Third-party Component | CVE | More information |
| Apache log4j | CVE-2021-44228 | Apache Log4j Remote Code Execution
DSN-2021-007: Dell Response to Apache Log4j Remote Code Execution Vulnerability |
影響を受ける製品と修復
Enterprise Hybrid Cloud 4.1.2 workflows is not impacted by this advisory, including packages Update 1 through 8.
Monitor the following advisories and apply workaround guidance and remediations as they become available:
Note: Dell EMC RecoverPoint for Virtual Machines plugin is not impacted by this advisory, all packages Update 1 through 8 are covered.
Monitor the following advisories and apply workaround guidance and remediations as they become available:
| CVE Addressed | Products | Link to Update |
| CVE-2021-44228 | VMware vCenter Server Appliance | VMSA-2021-0028.3 |
| VMware vRealize Automation 7.x | ||
| VMware vRealize Orchestrator 7.x | ||
| VMware NSX for Data Center for vSphere 6.x | ||
| VMware vRealize Log Insight 8.x | ||
| VMware vRealize Business for Cloud 7.x | ||
| Dell EMC Data Domain OS | DSA-2021-274
|
|
| Dell EMC Avamar | DSA-2021-277 | |
| Dell EMC VxRail | DSA-2021-265 | |
| VxBlock | See vce6771 (requires customer login) | |
| Dell EMC Unity | Monitor Knowledge Baste Article 194414 for advisory publication: https://www.dell.com/support/kbdoc/en-uk/000194414/dell-response-to-apache-log4j-remote-code-execution-vulnerability | |
| Dell EMC RecoverPoint for Virtual Machines | DSA-2021-284 |
Note: Dell EMC RecoverPoint for Virtual Machines plugin is not impacted by this advisory, all packages Update 1 through 8 are covered.
Enterprise Hybrid Cloud 4.1.2 workflows is not impacted by this advisory, including packages Update 1 through 8.
Monitor the following advisories and apply workaround guidance and remediations as they become available:
Note: Dell EMC RecoverPoint for Virtual Machines plugin is not impacted by this advisory, all packages Update 1 through 8 are covered.
Monitor the following advisories and apply workaround guidance and remediations as they become available:
| CVE Addressed | Products | Link to Update |
| CVE-2021-44228 | VMware vCenter Server Appliance | VMSA-2021-0028.3 |
| VMware vRealize Automation 7.x | ||
| VMware vRealize Orchestrator 7.x | ||
| VMware NSX for Data Center for vSphere 6.x | ||
| VMware vRealize Log Insight 8.x | ||
| VMware vRealize Business for Cloud 7.x | ||
| Dell EMC Data Domain OS | DSA-2021-274
|
|
| Dell EMC Avamar | DSA-2021-277 | |
| Dell EMC VxRail | DSA-2021-265 | |
| VxBlock | See vce6771 (requires customer login) | |
| Dell EMC Unity | Monitor Knowledge Baste Article 194414 for advisory publication: https://www.dell.com/support/kbdoc/en-uk/000194414/dell-response-to-apache-log4j-remote-code-execution-vulnerability | |
| Dell EMC RecoverPoint for Virtual Machines | DSA-2021-284 |
Note: Dell EMC RecoverPoint for Virtual Machines plugin is not impacted by this advisory, all packages Update 1 through 8 are covered.
回避策と緩和策
Follow workaround and mitigation information in articles and advisories linked in the Affected Products and Remediation section.
変更履歴
| Revision | Date | Description |
| 1.0 | 2021-12-14 | Initial Release |
| 1.1 | 2021-12-17 | Updated Content |
関連情報
法的免責事項
対象製品
Enterprise Hybrid Cloud, Enterprise Hybrid Cloud製品
Product Security Information文書のプロパティ
文書番号: 000194490
文書の種類: Dell Security Advisory
最終更新: 12 5月 2026
質問に対する他のDellユーザーからの回答を見つける
サポート サービス
お使いのデバイスがサポート サービスの対象かどうかを確認してください。