Skip to main content

DSA-2019-033: Dell EMC Data Domain Security Update for Oracle JRE Vulnerabilities

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

Medium

Details

Summary: 
Oracle JRE, which is an embedded component within Dell EMC Data Domain products, requires a security update to version 8u191 to address various vulnerabilities. 

Multiple components within the Dell EMC Data Domain have been updated to address various vulnerabilities. The embedded components are updated for the following vulnerabilities:  

  • CVE-2018-3180
    5.6 (AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)

For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm.  

To search for a particular CVE, use the database s search utility at http://web.nvd.nist.gov/view/vuln/search.

Multiple components within the Dell EMC Data Domain have been updated to address various vulnerabilities. The embedded components are updated for the following vulnerabilities:  

  • CVE-2018-3180
    5.6 (AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)

For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm.  

To search for a particular CVE, use the database s search utility at http://web.nvd.nist.gov/view/vuln/search.

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Affected products:  
 Dell EMC Data Domain versions prior to: 

  • DDOS 6.0.2.40

  • DDOS 6.1.2.30

  • DDOS 6.2.0.10

  • DDMC 6.1.2.30

  • DDMC 6.2.0.10

Dell EMC Data Domain versions:  

  • DDMC 2.0.1.1 and earlier


Remediation:
The following Dell EMC  Data Domain releases address this vulnerability:  
 
Dell EMC Data Domain version:  

  • DDOS 6.0.2.40

  • DDOS 6.1.2.30

  • DDOS 6.2.0.10

  • DDMC 6.1.2.30

  • DDMC 6.2.0.10

Dell EMC recommends all customers upgrade at the earliest opportunity. Contact Dell EMC Data Domain customer support to download the required rpm file and install it.

Dell EMC recommends all customers who currently using DDMC 2.0.1.1 or earlier, upgrade to DDMC 6.1.2.30 or DDMC 6.2.0.10

To upgrade your Dell EMC Data Domain system contact Dell EMC Data Domain Customer Support.
.



Affected products:  
 Dell EMC Data Domain versions prior to: 

  • DDOS 6.0.2.40

  • DDOS 6.1.2.30

  • DDOS 6.2.0.10

  • DDMC 6.1.2.30

  • DDMC 6.2.0.10

Dell EMC Data Domain versions:  

  • DDMC 2.0.1.1 and earlier


Remediation:
The following Dell EMC  Data Domain releases address this vulnerability:  
 
Dell EMC Data Domain version:  

  • DDOS 6.0.2.40

  • DDOS 6.1.2.30

  • DDOS 6.2.0.10

  • DDMC 6.1.2.30

  • DDMC 6.2.0.10

Dell EMC recommends all customers upgrade at the earliest opportunity. Contact Dell EMC Data Domain customer support to download the required rpm file and install it.

Dell EMC recommends all customers who currently using DDMC 2.0.1.1 or earlier, upgrade to DDMC 6.1.2.30 or DDMC 6.2.0.10

To upgrade your Dell EMC Data Domain system contact Dell EMC Data Domain Customer Support.
.



Related Information

Affected Products

Data Domain

Products

Data Domain, DD OS 6.2, DD OS 6.0, DD OS 6.1, Product Security Information
Article Properties
Article Number: 000001709
Article Type: Dell Security Advisory
Last Modified: 22 May 2021
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.