DSA-2025-258: Security Update for Dell NetWorker Multiple Third-Party Component Vulnerabilities
摘要: Dell NetWorker remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
本文适用于
本文不适用于
本文并非针对某种特定的产品。
本文并非包含所有产品版本。
影响
Critical
详情
| Third-party Component | CVEs | More Information |
| Apache CXF | CVE-2024-28752 | https://nvd.nist.gov/vuln/search |
| LogBack | CVE-2023-6378, CVE-2023-6481 | https://nvd.nist.gov/vuln/search |
| Spring Boot | CVE-2023-20873, CVE-2023-20883, CVE-2023-34055 | https://nvd.nist.gov/vuln/search |
| Spring Framework | CVE-2024-38819, CVE-2024-38828, CVE-2023-20860, CVE-2024-22262, CVE-2024-22243, CVE-2024-22259, CVE-2023-20861, CVE-2023-20863 | https://nvd.nist.gov/vuln/search |
| Spring Security | CVE-2023-34034, CVE-2023-20862, CVE-2023-34035, CVE-2024-22257 | https://nvd.nist.gov/vuln/search |
受影响的产品和补救措施
| Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
| NetWorker |
NetWorker Web UI File Level Recovery (FLR) NetWorker Authentication Server NetWorker vCenter User Interface (VCUI) NetWorker RESTAPI |
Versions prior to 19.13 | Version 19.13 or later | NetWorker Downloads Area |
| Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
| NetWorker |
NetWorker Web UI File Level Recovery (FLR) NetWorker Authentication Server NetWorker vCenter User Interface (VCUI) NetWorker RESTAPI |
Versions prior to 19.13 | Version 19.13 or later | NetWorker Downloads Area |
Notes:
- The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
- Versions prior to 19.13 means 19.12.x, 19.11.x, 19.10.x, 19.9.x, 19.8.x, 19.7.x, 19.6.x, 19.5.x, and 19.4.x family of releases that are still under standard support. For more information on Dell End-of-Life Documents for converged infrastructure, midrange and enterprise storage, and storage networking products refer to Dell End-of-Life Product List for Converged Infrastructure and Storage.
- The security advisory addresses vulnerabilities remediated in Dell NetWorker, version 19.13 or later, through the Oracle JDK 17 upgrade. Earlier versions, 19.12.x, 19.11.x, and 19.10.x, do not include this upgrade.
- Unless specified as impacted, the term “later releases” encompasses all NetWorker releases, under standard support, that are of a higher minor or major version than the specified release. Dell recommends that you always upgrade to the latest release/version for your product.
- Platforms: Windows & Linux (All variants and flavors are impacted).
解决方法和缓解措施
None
修订历史记录
| Revision | Date | Description |
| 1.0 | 2025-06-30 | Initial Release |
| 2.0 | 2025-08-19 | Updated the 'Affected and Remediated Versions' and 'Additional Information' sections |
相关信息
法律免责声明
受影响的产品
NetWorker Family文章属性
文章编号: 000338043
文章类型: Dell Security Advisory
上次修改时间: 19 8月 2025
从其他戴尔用户那里查找问题的答案
支持服务
检查您的设备是否在支持服务涵盖的范围内。