Unsolved
1 Rookie
•
1 Message
0
317
January 15th, 2025 01:24
Dell Open Manage Server Administrator- (OMSA) Patch for CVE-2024-50379/CVE-2024-56337
Official Documentation can be found here: Apache Tomcat® - Apache Tomcat 9 vulnerabilities
I know Dell is trying to phase out OMSA, but it is still supported at least until 2027.
There's a critical 9.8 CVE vulnerability that I can't see any patch released or mentioned for OMSA.
This one is a bit strange as they found the orginial fix wasn't 100% so they created CVE-2024-56337, irrespective, Apache Tomcat within the OMSA binary needs to be updated to Apache Tomcat 9.0.98.
Since OMSA uses tomcat and our Defender scans are mentioning this is active on OMSA, are there any plans in the works to release a patch for this anyone know when?
No Events found!
DELL-Joey C
Moderator
•
3.9K Posts
0
January 15th, 2025 08:20
Hi,
Support for OMSA is currently in sustenance mode. I have searched for any documentation regarding future release updates, but there are no tentative updates available. Additionally, there are no reports on the security vulnerability you mentioned at this time (https://dell.to/4gUrvGD).
I recommend raising a support case to have an engineer review OMSA for a potential patch if necessary.
dell4sm
1 Rookie
•
1 Message
0
January 15th, 2025 14:53
I confirm this issue. Apache Tomcat (9.0.97) bundled with the latest OMSA 11.1.0.0, A01 falls into the CVE vulnerability scope, it needs to be updated to 9.0.98 at the minimum for remediation. Please make the fix available for all your customers.
MadCoder332
1 Rookie
•
2 Posts
0
April 2nd, 2025 11:35
Same here:
I confirm this issue. Apache Tomcat (9.0.97) bundled with the latest OMSA 11.1.0.0, A01 falls into the CVE vulnerability scope, it needs to be updated to 9.0.98 at the minimum for remediation. Please make the fix available for all your customers.
MadCoder332
1 Rookie
•
2 Posts
0
April 2nd, 2025 12:54
@DELL-Joey C
Any update on this, its definitely a legit high CVE score on a supported Dell product
DELL-Joey C
Moderator
•
3.9K Posts
0
April 3rd, 2025 05:53
Hi,
Unfortunately, I am not able to check on the case if there is any open after my post comment to request for a call to technical support to raise a case. I also checked https://www.dell.com/support/security/en-us?dgc=sm&cid=1595898&lid=spr15833748735&refid=sm_COMMUNITY_spr15833748735&linkId=714935074 for any advisory logged, but I don't think it is listed. Due to that OMSA is in sustenance mode by engineering, I would suggest to contact support to create a case and raise to OMSA engineering for a patch.