Dell EMC PowerMax Embedded NAS (eNAS) False Positive Security Vulnerabilities for Apache Log4j (CVE-2021-4104, CVE-2019-17571, CVE-2022-23302, CVE-2022-23305, and CVE-2022-23307)
요약: This article provides a list of security vulnerabilities that cannot be exploited on Dell EMC PowerMax Embedded NAS (eNAS) version 8.1.15.*, but which may be identified by security scanners. ...
이 문서는 다음에 적용됩니다.
이 문서는 다음에 적용되지 않습니다.
이 문서는 특정 제품과 관련이 없습니다.
모든 제품 버전이 이 문서에 나와 있는 것은 아닙니다.
보안 문서 유형
Security KB
CVE 식별자
The CVE IDs are listed in the table below.
문제 요약
See the 'Recommendation' section below for details on each CVE.
권장 사항
The vulnerabilities that are listed in the table below are in order by the date on which PowerMax Embedded NAS (eNAS) Engineering determined that the PowerMax Embedded NAS (eNAS) version 8.1.15* was not vulnerable.
| Third-party Component | CVE ID | Summary of Vulnerability | Reason why Product is not Vulnerable | Date Determined False Positive |
| JMSAppender | CVE-2021-4104 | JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. | Describe the steps to address the issue.
|
1/4/2022 |
| SocketServer | CVE-2019-17571 | In Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely run arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. |
|
1/4/2022 |
| SMTP Appender | CVE-2020-9488 | Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages that are sent through that appender. |
|
2/17/2022 |
| JMSSink | CVE-2022-23302 | JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. |
|
2/17/2022 |
| JDBCAppender | CVE-2022-23305 | By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that are logged allowing unintended SQL queries to be run. |
|
2/17/2022 |
| Apache Chainsaw | CVE-2022-23307 | A deserialization issue is present in Apache Chainsaw. |
|
2/17/2022 |
법적 고지 사항
해당 제품
PowerMax, eNAS문서 속성
문서 번호: 000195522
문서 유형: Security KB
마지막 수정 시간: 13 5월 2026
버전: 3
다른 Dell 사용자에게 질문에 대한 답변 찾기
지원 서비스
디바이스에 지원 서비스가 적용되는지 확인하십시오.