DSA-2024-010: Security Update for Dell Data Protection Central for Multiple Third-Party Vulnerabilities
Samenvatting: Dell Data Protection Central remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Dit artikel is van toepassing op
Dit artikel is niet van toepassing op
Dit artikel is niet gebonden aan een specifiek product.
Niet alle productversies worden in dit artikel vermeld.
Impact
Critical
Gegevens
| Third-party Component | CVEs | More Information |
|---|---|---|
| IAM service |
CVE-2023-36054, CVE-2023-4039, CVE-2023-38039, CVE-2023-25193, CVE-2018-9234, CVE-2023-40217, CVE-2023-31484, CVE-2023-21930, CVE-2023-34035, CVE-2023-24329, CVE-2023-28322 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| node.js | CVE-2022-35255, CVE-2023-32002, CVE-2022-43548, CVE-2023-30589, CVE-2023-23918, CVE-2022-32212 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| Apache Tomcat | CVE-2023-28709 | https://nvd.nist.gov/vuln/detail/CVE-2023-28709 |
| get-func-name | CVE-2023-43646 | https://nvd.nist.gov/vuln/detail/CVE-2023-43646 |
| google guava | CVE-2023-2976 | https://nvd.nist.gov/vuln/detail/CVE-2023-2976 |
| cookiejar | CVE-2022-25901 | https://nvd.nist.gov/vuln/detail/CVE-2022-25901 |
| semver | CVE-2022-25883 | https://nvd.nist.gov/vuln/detail/CVE-2022-25883 |
| Okio | CVE-2023-3635 | https://nvd.nist.gov/vuln/detail/CVE-2023-3635 |
| spring boot | CVE-2023-20873, CVE-2023-20883 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| spring security | CVE-2023-34034 | https://nvd.nist.gov/vuln/detail/CVE-2023-34034) |
Getroffen producten en herstel
| Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
|---|---|---|---|---|
| Dell Data Protection Central | Data Protection Central OS Update (SUSE SLES 12 SP5) | Version 19.10 | Version 19.10.0-4 | Data Protection Central 19.10.0-4 |
| Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
|---|---|---|---|---|
| Dell Data Protection Central | Data Protection Central OS Update (SUSE SLES 12 SP5) | Version 19.10 | Version 19.10.0-4 | Data Protection Central 19.10.0-4 |
Platform: SUSE Linux Enterprise Server 12 SP5
See the latest ‘Dell Data Protection Central 19.10 Release Notes’ in Dell Data Protection Central 19.10 Release Notes | Dell US
See the latest ‘Dell Data Protection Central 19.10 Release Notes’ in Dell Data Protection Central 19.10 Release Notes | Dell US
Revisiegeschiedenis
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2024-01-17 | Initial Release |
Verwante informatie
Juridische verklaring van afstand
Getroffen producten
Data Protection CentralArtikeleigenschappen
Artikelnummer: 000221194
Artikeltype: Dell Security Advisory
Laatst aangepast: 19 sep. 2025
Vind antwoorden op uw vragen via andere Dell gebruikers
Support Services
Controleer of uw apparaat wordt gedekt door Support Services.