DSA-2020-105: Dell Avamar and NetWorker Security Update for Multiple Components

Summary: Multiple components within Dell Avamar and NetWorker require a security update to address various vulnerabilities.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

Critical

Details

Summary:   
Multiple components within Dell Avamar and NetWorker require a security update to address various vulnerabilities.

This security patch is a security update for various third-party software components installed on the Avamar and NetWorker nodes. The patch addresses multiple security vulnerabilities in those components. The patch applies to all Avamar and NetWorker Products running on the SLES platforms listed above. The products include Avamar single-node servers, multi-node servers, accelerator nodes, Avamar Virtual Edition systems, NetWorker Virtual Edition systems, Avamar Combined Proxy, Dell Backup and Recovery Manager Avamar (BRM), Dell Backup and Recovery Manager NetWorker (BRM), and Avamar Plug-in for vCloud Director.

This security patch also updates Java JRE to version 8u241 for Avamar Server 7.3 and later, Avamar Proxy 7.5.0 and later, NetWorker Virtual Edition 9.1 and later, Dell vCloud Director Data Protection Extension versions 2.0.5 and later, and Dell Avamar NDMP Accelerator 7.3 and later.

This security patch also updates Tomcat to version 8.5.51 for Avamar Server 7.3 and later.

See NVD (http://nvd.nist.gov/) for individual scores for each CVE.

This security patch is a security update for various third-party software components installed on the Avamar and NetWorker nodes. The patch addresses multiple security vulnerabilities in those components. The patch applies to all Avamar and NetWorker Products running on the SLES platforms listed above. The products include Avamar single-node servers, multi-node servers, accelerator nodes, Avamar Virtual Edition systems, NetWorker Virtual Edition systems, Avamar Combined Proxy, Dell Backup and Recovery Manager Avamar (BRM), Dell Backup and Recovery Manager NetWorker (BRM), and Avamar Plug-in for vCloud Director.

This security patch also updates Java JRE to version 8u241 for Avamar Server 7.3 and later, Avamar Proxy 7.5.0 and later, NetWorker Virtual Edition 9.1 and later, Dell vCloud Director Data Protection Extension versions 2.0.5 and later, and Dell Avamar NDMP Accelerator 7.3 and later.

This security patch also updates Tomcat to version 8.5.51 for Avamar Server 7.3 and later.

See NVD (http://nvd.nist.gov/) for individual scores for each CVE.

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Affected products:    

  • Dell Avamar Server hardware appliance Gen4S with versions 7.3 and later running SUSE Linux Enterprise 11 SP1

  • Dell Avamar Server hardware appliance Gen4T with versions 7.3 and later running SUSE Linux Enterprise 11 SP3

  • Dell Avamar Server hardware appliance Gen4S/Gen4T with versions 7.3 and later running SUSE Linux Enterprise 11 SP4

  • Dell Avamar Server hardware appliance Gen4S/Gen4T with versions 19.2 running SUSE Linux Enterprise 12 SP4

  • Dell Avamar Virtual Edition versions 7.3 and later running SUSE Linux Enterprise 11 SP3

  • Dell Avamar Virtual Edition versions 7.3 and later running SUSE Linux Enterprise 11 SP4 (including Azure and AWS deployments since 7.5.1)

  • Dell Avamar Virtual Edition versions 19.2 and later running SUSE Linux Enterprise 12 SP4 (including Azure and AWS deployments)

  • Dell Avamar NDMP Accelerator 7.3 and later running SUSE Linux Enterprise 11 SP1, SP3, and 12 SP4

  • Dell Avamar VMware Image Proxy versions 7.3 and later running SUSE Linux Enterprise 11 SP1 or SUSE Linux Enterprise 11 SP3

  • Dell Avamar VMware Image Proxy versions 7.5.1 and later running SUSE Linux Enterprise 12 SP1 or SUSE Linux Enterprise 12 SP4

  • Dell NetWorker Virtual Edition (NVE) versions 9.1.x, 9.2.x, 18.x, and later running SUSE Linux Enterprise 11 SP3 or SP4

  • Dell Backup and Recovery Manager (Avamar and NetWorker) versions v1.3 and v1.3.1 running SUSE Linux Enterprise 11 SP3

  • Dell vCloud Director Data Protection Extension versions 2.0.5 and later running SUSE Linux Enterprise 11 SP3

  • Dell Integrated Data Protection Appliance (IDPA) 2.0, 2.1, 2.2, 2.3, 2.4, and 2.5

Note:   
The CVEs remedied by this security update are listed in the Release Notes. The Release Notes lists not only the new CVEs remedied by this update, but all the past CVEs in this cumulative update.

For Dell Avamar Servers running SUSE Linux Enterprise 11 SP1 or SP3, that the OS versions are end of life, the security update only remedies CVEs which SUSE remedies and updates some third party packages, such as JRE and Tomcat. It is recommended to upgrade Avamar servers to SUSE Linux Enterprise 11 SP4 prior to applying the OS Security Update.

Apply the platform security patch to Avamar software 7.3 and later and to NetWorker Virtual Edition.

The following platform security patch packages are now available to be installed:   

The Security Update for Avamar Virtual Edition and NetWorker Virtual Edition is customer installable. See the links below for download and installation instructions.

The installation process requires shutting down the server software, rebooting all the nodes, and restarting the server software, and so, appropriate time must be scheduled and allocated to perform this full process.

Dell strongly recommends that all customers upgrade at the earliest opportunity.

To schedule platform security patch installation, or to upgrade your server, contact Dell Customer Support at https://support.emc.com/.

See the following Dell articles for Security Update (Rollup) Installation instructions:   

Read more in the Release Notes: 

Affected products:    

  • Dell Avamar Server hardware appliance Gen4S with versions 7.3 and later running SUSE Linux Enterprise 11 SP1

  • Dell Avamar Server hardware appliance Gen4T with versions 7.3 and later running SUSE Linux Enterprise 11 SP3

  • Dell Avamar Server hardware appliance Gen4S/Gen4T with versions 7.3 and later running SUSE Linux Enterprise 11 SP4

  • Dell Avamar Server hardware appliance Gen4S/Gen4T with versions 19.2 running SUSE Linux Enterprise 12 SP4

  • Dell Avamar Virtual Edition versions 7.3 and later running SUSE Linux Enterprise 11 SP3

  • Dell Avamar Virtual Edition versions 7.3 and later running SUSE Linux Enterprise 11 SP4 (including Azure and AWS deployments since 7.5.1)

  • Dell Avamar Virtual Edition versions 19.2 and later running SUSE Linux Enterprise 12 SP4 (including Azure and AWS deployments)

  • Dell Avamar NDMP Accelerator 7.3 and later running SUSE Linux Enterprise 11 SP1, SP3, and 12 SP4

  • Dell Avamar VMware Image Proxy versions 7.3 and later running SUSE Linux Enterprise 11 SP1 or SUSE Linux Enterprise 11 SP3

  • Dell Avamar VMware Image Proxy versions 7.5.1 and later running SUSE Linux Enterprise 12 SP1 or SUSE Linux Enterprise 12 SP4

  • Dell NetWorker Virtual Edition (NVE) versions 9.1.x, 9.2.x, 18.x, and later running SUSE Linux Enterprise 11 SP3 or SP4

  • Dell Backup and Recovery Manager (Avamar and NetWorker) versions v1.3 and v1.3.1 running SUSE Linux Enterprise 11 SP3

  • Dell vCloud Director Data Protection Extension versions 2.0.5 and later running SUSE Linux Enterprise 11 SP3

  • Dell Integrated Data Protection Appliance (IDPA) 2.0, 2.1, 2.2, 2.3, 2.4, and 2.5

Note:   
The CVEs remedied by this security update are listed in the Release Notes. The Release Notes lists not only the new CVEs remedied by this update, but all the past CVEs in this cumulative update.

For Dell Avamar Servers running SUSE Linux Enterprise 11 SP1 or SP3, that the OS versions are end of life, the security update only remedies CVEs which SUSE remedies and updates some third party packages, such as JRE and Tomcat. It is recommended to upgrade Avamar servers to SUSE Linux Enterprise 11 SP4 prior to applying the OS Security Update.

Apply the platform security patch to Avamar software 7.3 and later and to NetWorker Virtual Edition.

The following platform security patch packages are now available to be installed:   

The Security Update for Avamar Virtual Edition and NetWorker Virtual Edition is customer installable. See the links below for download and installation instructions.

The installation process requires shutting down the server software, rebooting all the nodes, and restarting the server software, and so, appropriate time must be scheduled and allocated to perform this full process.

Dell strongly recommends that all customers upgrade at the earliest opportunity.

To schedule platform security patch installation, or to upgrade your server, contact Dell Customer Support at https://support.emc.com/.

See the following Dell articles for Security Update (Rollup) Installation instructions:   

Read more in the Release Notes: 

Workarounds & Mitigations

None

Revision History

Revision

Date

Description

1.0

2020-06-22

Initial Release

Related Information

Affected Products

Avamar, Avamar Client, Avamar Client for VMware, Avamar Client for Windows, Avamar Data Migration Enabler, Avamar Data Store, Avamar Data Store Gen3, Avamar Data Store Gen4S, Avamar Data Store Gen4T, Avamar Data Transport , Avamar Desktop/Laptop Option, Avamar Extended Retention, Avamar Media Access Node, Avamar Plug-in, Avamar Plug-in for Exchange 2003, Avamar Plug-in for Exchange 2007, Avamar Plug-in for Exchange VSS, Avamar Plug-in for IBM DB2, Avamar Plug-in for Lotus Domino, Avamar Plug-in for NDMP, Avamar Plug-in for Oracle, Avamar Plug-in for SAP with Oracle, Avamar Plug-in for SharePoint, Avamar Plug-in for SharePoint VSS, Avamar Plug-in for SQL, Avamar Plug-in for Sybase ASE, Avamar REST API, Avamar Server, Avamar Virtual Edition, Avamar with CloudBoost, Backup & Recovery Manager Avamar, PowerProtect Data Protection Software, Integrated Data Protection Appliance Family, PowerProtect Data Protection Hardware, Integrated Data Protection Appliance Software, Multiple Systems Management, NetWorker, NetWorker Series, NetWorker for OpenVMS, NetWorker Management Console, NetWorker Module, NetWorker Module for Databases and Applications, NetWorker Module for MEDITECH, NetWorker Module for Microsoft, NetWorker SnapImage Module, OpenStack Data Protection Extension, Product Security Information, vRealize Data Protection Extension for Avamar, vRealize Data Protection Extension for NetWorker ...
Article Properties
Article Number: 000153677
Article Type: Dell Security Advisory
Last Modified: 19 Sept 2025
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.