posted by martyb on Friday January 12 2018, @02:44AM   Printer-friendly
While everyone was screaming about Meltdown and Spectre, another urgent security fix was already in progress for many corporate data centers and cloud providers who use products from Dell's EMC and VMware units. A trio of critical, newly reported vulnerabilities in EMC and VMware backup and recovery tools—EMC Avamar, EMC NetWorker, EMC Integrated Data Protection Appliance, and vSphere Data Protection—could allow an attacker to gain root access to the systems or to specific files, or inject malicious files into the server's file system. These problems can only be fixed with upgrades. While the EMC vulnerabilities were announced late last year, VMware only became aware of its vulnerability last week.

[...] For those familiar with the architecture of these products, the vulnerabilities may not be a surprise—EMC Avamar and the other applications use Apache Tomcat, which was patched multiple times last year to address critical security vulnerabilities. However, it's not clear whether these patches were incorporated into earlier updates of the EMC and VMware products or if any of the bugs just fixed in updates of the EMC/VMware products were Tomcat related.


    Spam but not far from truth. Wonder how long the NSA sat on these before finding People to discover them. hope my tinfoil is just on tight. Hmm.... tomorrow's stories to confuse consumers.... rohingya? North Korea? follow the 11 pointed star. she knows De wae