メイン コンテンツに進む
  • すばやく簡単にご注文が可能
  • 注文内容の表示、配送状況をトラック
  • 会員限定の特典や割引のご利用
  • 製品リストの作成とアクセスが可能
  • 「Company Administration(会社情報の管理)」では、お使いのDell EMCのサイトや製品、製品レベルでのコンタクト先に関する情報を管理できます。

文書番号: 000194496


Additional Information for Dell Endpoint Security with regard to Apache Log4j Remote Code Execution Vulnerability (CVE-2021-44228)

概要: This article outlines additional information about the effects of CVE-2021-44228 for Dell Endpoint Security applications.

文書の内容


セキュリティ文書の種類

Security KB

CVE識別子

CVE-2021-44228

問題の概要

Dell Endpoint Security applications leverage Dell-hosted infrastructure where services using Log4j may experience side-effects based on CVE-2021-44228.

Related Products:
Dell Security Management Server
Dell Data Protection | Encryption Server
Dell Security Management Server Virtual
Dell Data Protection | Encryption Server - Virtual
Supporting Infrastructure

詳細

Dell Security Management Server and Dell Security Management Server Virtual version 11.2 and earlier are unaffected by CVE-2021-44228.

Dell Endpoint Security uses a version of Log4j that is unaffected by CVE-2021-44228 to output logging information for Java applications in the following services:

  • Dell Compatibility Server
  • Dell Compliance Reporter (deprecated in Dell Security Management Server 10.1)
  • Dell Core Server Proxy
  • Dell Device Server
  • Dell Message Broker
  • Dell Document Store (deprecated in Dell Data Protection | Encryption Server 9.1.5)
  • Dell Recovery Server
  • Dell Security Server
  • Dell Security Server Proxy
Dell Endpoint Security leverages several cloud-based services that are affected by CVE-2021-44228 which will remain disabled until the vulnerability is patched.

Functionality that is affected includes:
  • In-Server Product Bulletins
    • This allows for all Dell Security Management Servers to pick up product notifications published by Dell.
  • Dell Security Management Server Virtual Updates
    • Dell Security Management Server Virtual versions before 9.11 (launched in May 2018) cannot downloads server updates.
  • Dell Data Guardian geo-location
    • Servers managing Dell Data Guardian managed documents cannot retrieve geolocation data.
  • Dell Endpoint Security Suite Enterprise tenant certificate validation
    • New Dell Endpoint Security Suite Enterprise tenants cannot be generated.
Note: Dell Endpoint Security client applications (Dell Encryption, Dell Endpoint Security Suite Enterprise, Dell Data Guardian, and so forth) are not affected by CVE-2021-44228 (see DSN-2021-007: Dell Response to Apache Log4j Remote Code Execution Vulnerability)

For additional information about the Network Requirements for the Dell Security Management Server or the Dell Security Management Server Virtual, see Dell Data Security / Dell Data Protection Server Network and Firewall Requirements.

To contact support, reference Dell Data Security International Support Phone Numbers.
Go to TechDirect to generate a technical support request online.
For additional insights and resources, join the Dell Security Community Forum.

推奨事項

No administrative action is needed at this time for the Dell Security Management Server or Dell Security Management Server Virtual.

文書のプロパティ


影響を受ける製品

Dell Endpoint Security Suite Enterprise, Product Security Information

最後に公開された日付

16 12月 2021

バージョン

2

文書の種類

Security KB