iTnews Asia
  • Home
  • News
  • Security

Dell moves on Apache Struts 2 vulnerability

Dell moves on Apache Struts 2 vulnerability

Avamar, backup appliance affected.

By Richard Chirgwin on Feb 26, 2024 11:46AM

Dell has begun working to patch a late-2023 critical vulnerability in Apache Struts 2, which has been inherited by a number of its Avamar and Integrated Data Protection Appliance (IDPA) products.

Avamar is a suite of data protection software that supports physical, virtual, and cloud environments.

In December, the Apache Foundation disclosed CVE-2023-50164, advising all users to upgrade to Struts 2.5.33 or Struts 6.3.0.2 or greater. Within days, proof-of-concept code was published.

“An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file," Apache’s advisory stated.

That sent a number of vendors on a hunt for whether their products had inherited the bug.

Dell has joined peers such as Cisco in advising of its vulnerability to CVE-2023-50164.

So far, fixes are available for various Avamar products in the version 19.10 branch; Avamar Virtual Edition for VMware ESXi and vSphere; and IDPA PowerProtect DP Series version 2.7.4 and older.

Other Avamar versions are awaiting a fix, expected in April.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
apache avamar dell security

Related Articles

  • Beware the pitfalls of using a ‘DIY security’ approach
  • AI transforms cyberattacks, but human trust remains the weakest link
  • How severe will ransomware attacks become in 2026?
  • Identity is now the new cybersecurity battlefield
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Beware the pitfalls of using a ‘DIY security’ approach

Beware the pitfalls of using a ‘DIY security’ approach

AI transforms cyberattacks, but human trust remains the weakest link

AI transforms cyberattacks, but human trust remains the weakest link

Zuellig Pharma launches Asia's first healthcare data exchange platform

Zuellig Pharma launches Asia's first healthcare data exchange platform

Toyota's Indian unit warns of a possible customer data breach

Toyota's Indian unit warns of a possible customer data breach

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.