Zu den Hauptinhalten
  • Bestellungen schnell und einfach aufgeben
  • Bestellungen anzeigen und den Versandstatus verfolgen
  • Profitieren Sie von exklusiven Prämien und Rabatten für Mitglieder
  • Erstellen Sie eine Liste Ihrer Produkte, auf die Sie jederzeit zugreifen können.
  • Verwalten Sie mit der Unternehmensverwaltung Ihre Dell EMC Seiten, Produkte und produktspezifischen Kontakte.

Data Protection Advisor: Manual remediation for Log4j vulnerabilities-Windows commands only (CVE-2021-44228 and CVE-2021-45046)

Zusammenfassung: This article provides instructions for manual remediation of a DPA Agent running on a Microsoft Windows node that is affected by the Apache Log4j vulnerabilities (CVE-2021-44228 and CVE-2021-45046). ...

Dieser Artikel gilt für   Dieser Artikel gilt nicht für 

Weisungen

These instructions require only Windows native commands, access to the server (for example, Remote Desktop), and Windows Explorer.

These instructions can be applied to any type of Windows DPA installation including the DPA Application, DPA Datastore, and Standalone DPA Agent (installed alone on a server or on another type of application server).

See the linked Dell Security Advisory for more information about the Apache Log4j vulnerabilities: For questions or assistance with these instructions, contact Dell Technical Support.

Steps for manual remediation:

Note:
  • Windows Administrator privileges and access is required.
  • No external utilities are required for these steps.
 
  1. Stop the DPA Agent service. Do this by using the Windows Services snap-in or from the command line using the Windows PowerShell.

From the Windows PowerShell window, if this is an Agent installation on the DPA Application or DPA Datastore, the command is:

dpa agent stop

From the Windows PowerShell window, if this is a Standalone DPA Agent installation the command is:

<dpa agent install path>\dpa stop

Example:   
C:\Program Files\EMC\DPA\agent\etc\dpa stop

  1. Open a Windows Explorer window. Go to the <dpa_installation_path>\agent\lib directory.
 
pic_00.JPG
 
  1. For each of the six .jar files below, make a backup copy of the .jar file. Copy and rename with _bak extension or something similar (Example is demonstrated with one of the files).
 
pic_01.JPG
 
  1. Change the .jar file extension from .jar to .zip.
 
pic_02.JPG
 
pic_03.JPG
 
  1. For each of the six .zip files, double-click the file to descend into the .zip and directory structure (Example that is demonstrated with one of the files).
pic_04.JPG
 
  1. Drill down the directory structure to the following location:
...\dpaagent_moddatadomain_analysis.zip\org\apache\logging\log4j\core\lookup\
 
pic_05.JPG
 
  1. Delete the JndiLookup.class file.
 
pic_06.JPG
 
pic_07.JPG 
  1. Navigate back to the ...\agent\lib directory. Note: The file size has changed slightly.
 
pic_08.JPG
 
  1. Rename the file extension from .zip to .jar.
 
pic_09.JPG
 
pic_10.JPG
 
  1. After this procedure is complete for all 6 .jar files, the workaround is complete.
  2. Start the DPA Agent service. Do this by using the Windows Services snap-in or from the command line using the Windows PowerShell.

From the Windows PowerShell window, if this is an Agent installation on the DPA Application or DPA Datastore, the command is:

dpa agent start

From the Windows PowerShell window, if this is a Standalone DPA Agent installation, the command is:

<dpa agent install path>\dpa start

Example:   
C:\Program Files\EMC\DPA\agent\etc\dpa start

  1. If wanted, rerun a data collection Request to ensure it continues to work without issue. In the below example, we have verified with the Data Domain Analysis Request.

pic_11_02.JPG


For questions or assistance with these instructions, contact Dell Technical Support.
 
Artikeleigenschaften
Artikelnummer: 000194903
Artikeltyp: How To
Zuletzt geändert: 14 Dez. 2022
Version:  4
Antworten auf Ihre Fragen erhalten Sie von anderen Dell NutzerInnen
Support Services
Prüfen Sie, ob Ihr Gerät durch Support Services abgedeckt ist.
Artikeleigenschaften
Artikelnummer: 000194903
Artikeltyp: How To
Zuletzt geändert: 14 Dez. 2022
Version:  4
Antworten auf Ihre Fragen erhalten Sie von anderen Dell NutzerInnen
Support Services
Prüfen Sie, ob Ihr Gerät durch Support Services abgedeckt ist.