QID 378055

Date Published: 2023-03-16

QID 378055: Dell NetWorker Security Update for an Apache Tomcat Vulnerability (DSA-2023-040)

Dell NetWorker is a suite of enterprise level data protection software that unifies and automates backup to tape, disk-based, and flash-based storage media across physical and virtual environments for granular and disaster recovery.

Affected NetWorker Versions:
Prior to Networker version 19.7.0.3

QID Detection Logic (Authenticated):
This QID checks Windows registry "HKLM\SOFTWARE\Legato\NetWorker" and "HKLM\SOFTWARE\Wow6432Node\Legato\NetWorker" to see if vulnerable version of Dell NetWorker is installed.

Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header. The NetWorker Authentication Service component of NetWorker is impacted by this Apache Tomcat Vulnerability

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Customers are advised to refer to Dell Security Advisory DSA-2023-040 for more information about this vulnerability.

    CVEs related to QID 378055

    Software Advisories
    Advisory ID Software Component Link
    DSA-2023-040 URL Logo www.dell.com/support/kbdoc/en-in/000208180/dsa-2023-040-dell-networker-security-update-for-an-apache-tomcat-vulnerability