VPLEX: Metro Node False Positive Security Vulnerabilities
요약: This article provides a list of security vulnerabilities that cannot be exploited on Dell VPLEX GeoSynchrony 6.x SuSE Linux Enterprise Server (SLES) OS but which may be identified by security scanners. ...
이 문서는 다음에 적용됩니다.
이 문서는 다음에 적용되지 않습니다.
이 문서는 특정 제품과 관련이 없습니다.
모든 제품 버전이 이 문서에 나와 있는 것은 아닙니다.
보안 문서 유형
Security KB
CVE 식별자
The CVE IDs are listed in the table below.
문제 요약
See the 'Recommendation' section below for details on each CVE.
권장 사항
The vulnerabilities listed in the table below are in order by the date on which VPLEX/Metro Node Engineering determined that the VPLEX GeoSynchrony and Metro Node OS SLES are not vulnerable.
| Embedded Component | CVE ID | Summary of Vulnerability | Reason why Product is not Vulnerable | Date Determined False Positive |
| Spring4Shell | CVE-2022-22963 | In Spring Cloud Function versions 3.1.6, 3.2.2, and earlier unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources. | SUSE does not include the Spring framework in its products, so none of our products are affected by this issue.
SUSE Bugzilla entry: 1197804 [RESOLVED / INVALID] |
January 10, 2022 |
| Spring4Shell | CVE-2022-22965 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) using data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, (the default), it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it. | SUSE does not include the Spring framework in its products, so none of our products are affected by this issue.
SUSE Bugzilla entry: 1197879 [RESOLVED / INVALID] |
January 10, 2022 |
추가 정보
Official guidance: (1) Spring RCEs CVE-2022-22963 & CVE-2022-22965 - Product and Application Security Knowledge Base - PAS Confluence (dell.com)
Related EE ticket:[VPLEX-43888] CVE-2022-22963 & CVE-2022-22965 Vulnerability Impact on VPLEX - ISG Jira (internal) (emc.com)
Related EE ticket:[VPLEX-43888] CVE-2022-22963 & CVE-2022-22965 Vulnerability Impact on VPLEX - ISG Jira (internal) (emc.com)
법적 고지 사항
해당 제품
metro node mn-114, VPLEX Series, VPLEX VS2, VPLEX VS6문서 속성
문서 번호: 000198111
문서 유형: Security KB
마지막 수정 시간: 13 5월 2026
버전: 3
다른 Dell 사용자에게 질문에 대한 답변 찾기
지원 서비스
디바이스에 지원 서비스가 적용되는지 확인하십시오.