UCC Edge: Logback Vulnerability False Positive (CVE-2021-42550)
요약: This article provides a list of security vulnerabilities that cannot be exploited on Dell UCC Edge 2.0.2, but which may be identified by security scanners.
이 문서는 다음에 적용됩니다.
이 문서는 다음에 적용되지 않습니다.
이 문서는 특정 제품과 관련이 없습니다.
모든 제품 버전이 이 문서에 나와 있는 것은 아닙니다.
보안 문서 유형
Security KB
CVE 식별자
CVE-2021-42550
문제 요약
See the 'Recommendation' section below for details on each CVE.
권장 사항
The vulnerabilities listed in the table below are in order by the date on which UCC Edge Engineering determined that the UCC Edge 2.0.2 was not vulnerable.
| Third-party Component | CVE ID | Summary of Vulnerability | Reason why Product is not Vulnerable | Date Determined False Positive |
| Logback | CVE-2021-42550 | In Logback version 1.2.7 and earlier versions, an attacker with the required privileges to edit configurations files may potentially craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers. | Logback 1.2.3 is used in our released product of UCC Edge 2.0.2 but the application is not using any configuration file for Logback, which makes it not possible to exploit this vulnerability. | 2022-01-19 |
법적 고지 사항
해당 제품
UCC Edge제품
Product Security Information문서 속성
문서 번호: 000195400
문서 유형: Security KB
마지막 수정 시간: 19 9월 2025
버전: 2
다른 Dell 사용자에게 질문에 대한 답변 찾기
지원 서비스
디바이스에 지원 서비스가 적용되는지 확인하십시오.