QID 378055
Date Published: 2023-03-16
QID 378055: Dell NetWorker Security Update for an Apache Tomcat Vulnerability (DSA-2023-040)
Dell NetWorker is a suite of enterprise level data protection software that unifies and automates backup to tape, disk-based, and flash-based storage media across physical and virtual environments for granular and disaster recovery.
Affected NetWorker Versions:
Prior to Networker version 19.7.0.3
QID Detection Logic (Authenticated):
This QID checks Windows registry "HKLM\SOFTWARE\Legato\NetWorker" and "HKLM\SOFTWARE\Wow6432Node\Legato\NetWorker" to see if vulnerable version of Dell NetWorker is installed.
Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header. The NetWorker Authentication Service component of NetWorker is impacted by this Apache Tomcat Vulnerability
CVEs related to QID 378055
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| DSA-2023-040 |
|