DSA-2021-297: Dell EMC Streaming Data Platform Security Update for Apache Log4j Remote Code Execution Vulnerability
Summary: Dell EMC Streaming Data Platform remediation is available for the Apache Log4j Remote Code Execution Vulnerability that may be exploited by malicious users to compromise the affected system. Dell recommends implementing this remediation as soon as possible in light of the critical severity of the vulnerability. ...
Bu makale şunlar için geçerlidir:
Bu makale şunlar için geçerli değildir:
Bu makale, belirli bir ürüne bağlı değildir.
Bu makalede tüm ürün sürümleri tanımlanmamıştır.
Impact
Critical
Details
| Third-Party Component | CVEs | More information |
| Apache Log4j | CVE-2021-44228 | Apache Log4j Remote Code Execution |
| CVE-2021-45046 | ||
| CVE-2021-45105 | ||
| CVE-2021-44832 |
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.
| Third-Party Component | CVEs | More information |
| Apache Log4j | CVE-2021-44228 | Apache Log4j Remote Code Execution |
| CVE-2021-45046 | ||
| CVE-2021-45105 | ||
| CVE-2021-44832 |
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.
Etkilenen Ürünler ve Düzeltme
|
Note: Dell EMC Streaming Data Platform (SDP) has remediated CVE-2021-44228, CVE-2021-45046 in version 1.3.1 and later. Although CVE-2021-45105, CVE-2021-44832 were not exploitable in SDP, Apache Log4j is upgraded to 2.17.1 in SDP 1.3.1.1
|
Note: Dell EMC Streaming Data Platform (SDP) has remediated CVE-2021-44228, CVE-2021-45046 in version 1.3.1 and later. Although CVE-2021-45105, CVE-2021-44832 were not exploitable in SDP, Apache Log4j is upgraded to 2.17.1 in SDP 1.3.1.1
Revision History
| Revision | Date | Description |
| 1.0 | 2021-12-16 | Initial Release |
| 1.1 | 2021-12-17 | Updated the SDP 1.3.1 download link |
| 1.2 | 2022-01-19 | Added version 1.3.1.1 and additional CVE-2021-45105, CVE-2021-44832 |
Related Information
Yasal Uyarı
Etkilenen Ürünler
Streaming Data PlatformÜrünler
Streaming Data Platform FamilyMakale Özellikleri
Article Number: 000194627
Article Type: Dell Security Advisory
Son Değiştirme: 05 Kas 2025
Sorularınıza diğer Dell kullanıcılarından yanıtlar bulun
Destek Hizmetleri
Aygıtınızın Destek Hizmetleri kapsamında olup olmadığını kontrol edin.