List of software (un)affected by the log4shell CVEs

June 15, 2022 ยท View on GitHub

About this list

0-9 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

C

SupplierProductVersion (see Status)Status CVE-2021-4104Status CVE-2021-44228Status CVE-2021-45046Status CVE-2021-45105NotesLinks
Campbell ScientificAllNot vulnlink
CarrierAllNot vulnlink
CircleCIAlllink
C4b XPHONEAllC4b XPHONE Link
CamundaAllCamunda Forum Link
Canary LabsAllNot vulnNot vulnNot vulnNot vulnCanary Labs Advisory Link
CanonApplications integrated with Vitrea (iCAD, Invia, Medis, Mevis, Mirada, Olea and Tomtec)Not vulnsource
CanonDR Products (CXDI_NE)Omnera, Flexpro, Soltus and moreNot vulnsource
CanonCT Medical Imaging ProductsNot vulnsource
CanonEasy VizNot vulnsource
CanonEye-Care ProductsNot vulnsource
CanonMR Medical Imaging ProductsNot vulnsource
CanonNM Medical Imaging ProductsNot vulnsource
CanonOlea SphereNot vulnsource
CanonRialto7.xVulnerableContact customer supportsource
CanonRialto Connect and VaultNot vulnsource
CanonSolution Health (Cloud)Not vulnsource
CanonSolution Health (On-Prem)VulnerableContact customer supportsource
CanonUL Medical Imaging ProductsNot vulnsource
CanonVitrea Advanced7.xVulnerableSee source for mitigationssource
CanonVitrea Connection8.xVulnerableContact customer supportsource
CanonVitrea ViewNot vulnsource
CanonVL Alphenix Angio Workstation (AWS)Vulnerablesource
CanonVL Infinix-i and Alphenix DFPNot vulnsource
CanonVL Infinix-i Angio Workstation (AWS)Not vulnsource
CanonXR Medical Imaging ProductsNot vulnsource
CanonZillionNot vulnsource
CapStormCopystormInvestigation
Carbon BlackCloud Workload ApplianceWorkaroundMore information on pages linked bottom of blogpost (behind login)source
Carbon BlackEDR ServersWorkaroundMore information on pages linked bottom of blogpost (behind login)source
CarbonBlackAllCarbonBlack Advisory
CareStreamAllNot vulnNot vulnNot vulnNot vulnsource
CAS genesisWorldAllCAS genesisWorld Link
CaseWareCloudAllNot vulnFixsource
CaseWareIDEAAllNot vulnNot vulnNot vulnNot vulnsource
CaseWareWorkingPapersAllNot vulnNot vulnNot vulnNot vulnsource
CatalogicCloudCasaAllNot vulnNot vulnNot vulnNot vulnsource
Cato NetworksAllCato Networks Blog Post
CendioThinLincAllNot vulnNot vulnNot vulnNot vulnsource
CepheidC360Not vulnNot vulnNot vulnNot vulnsource
CepheidGeneXpertInvestigationsource
CerberusFTPNot vulnNot vulnNot vulnNot vulnsource
Cerberus FTPAllCerberus Article
CerebrateAllAllNot vulnNot vulnNot vulnNot vulnsource
CerebroElasticsearch Web AdminAllNot vulnNot vulnNot vulnNot vulnUses logback for loggingsource
Chaser SystemsdiscrimiNAT FirewallAllNot vulnNot vulnNot vulnNot vulnsource
Chatsworth ProductseConnect PDUNot vulnNot vulnNot vulnNot vulnhttps://user-images.githubusercontent.com/89155495/146845501-b2186f1b-ccce-4f3d-a2c3-373db2eed9f0.png
Check PointCloudGuardAllNot vulnNot vulnNot vulnNot vulnsource
Check PointHarmony Endpoint & Harmony MobileAllNot vulnNot vulnNot vulnNot vulnsource
Check PointInfinity PortalAllNot vulnNot vulnNot vulnNot vulnsource
Check PointQuantum Security GatewayAllNot vulnNot vulnNot vulnNot vulnsource
Check PointQuantum Security ManagementAllNot vulnNot vulnNot vulnNot vulnsource
Check PointSMBAllNot vulnNot vulnNot vulnNot vulnsource
Check PointThreatCloudAllNot vulnNot vulnNot vulnNot vulnsource
CheckMKAllCheckMK Forum
ChefAutomateAllNot vulnNot vulnNot vulnNot vulnsource
ChefBackendAllNot vulnNot vulnNot vulnNot vulnsource
ChefInfra ServerAllNot vulnNot vulnNot vulnNot vulnsource
CiphermailAllCiphermail Blog Post
CISCAT Lite4.13.1FixFixFixsource
CISCAT Pro Assessor v3 Full and Dissolvable3.0.78FixFixFixsource
CISCAT Pro Assessor v44.13.1FixFixFixsource
CISCAT Pro Assessor v4 Service1.13.1FixFixFixsource
CISCAT Pro DashboardNot vulnNot vulnNot vulnNot vulnsource
CISCSAT Pro1.7.2FixFixFixsource
CISHosted CSATNot vulnNot vulnNot vulnNot vulnsource
CISWorkBenchNot vulnNot vulnNot vulnNot vulnsource
CiscoACI Multi-Site OrchestratorNot vulnNot vulnNot vulnNot vulnsource
CiscoACI Virtual EdgeNot vulnNot vulnNot vulnNot vulnsource
CiscoAdaptive Security Appliance (ASA) SoftwareNot vulnNot vulnNot vulnNot vulnsource
CiscoAdaptive Security Device ManagerNot vulnNot vulnNot vulnNot vulnsource
CiscoAdaptive Security virual Appliance (ASAv)AllNot vulnNot vulnNot vulnsource
CiscoAdvanced Web Security Reporting ApplicationAllNot vulnNot vulnNot vulnsource
CiscoAireOS Wireless LAN ControllersAllNot vulnNot vulnNot vulnsource
CiscoAironet 1560 Series Access PointsNot vulnNot vulnNot vulnNot vulnsource
CiscoAironet 1810 Series OfficeExtend Access PointsNot vulnNot vulnNot vulnNot vulnsource
CiscoAironet 1810w Series Access PointsNot vulnNot vulnNot vulnNot vulnsource
CiscoAironet 1815 Series Access PointsNot vulnNot vulnNot vulnNot vulnsource
CiscoAironet 1830 Series Access PointsNot vulnNot vulnNot vulnNot vulnsource
CiscoAironet 1850 Series Access PointsNot vulnNot vulnNot vulnNot vulnsource
CiscoAironet 2800 Series Access PointsNot vulnNot vulnNot vulnNot vulnsource
CiscoAironet 3800 Series Access PointsNot vulnNot vulnNot vulnNot vulnsource
CiscoAironet Access PointsAllNot vulnNot vulnNot vulnsource
CiscoAMP Virtual Private Cloud ApplianceAllNot vulnNot vulnNot vulnsource
CiscoAnyConnect Secure Mobility ClientAllNot vulnNot vulnNot vulnNot vulnsource
CiscoAppDynamicsMultipleNot vulnFixFixNot vulnSee advisory for complete list of fixed versions per componentsource
CiscoAppDynamics with Cisco Secure ApplicationMultipleNot vulnFixFixNot vulnsource
CiscoApplication Policy Infrastructure Controller (APIC)Not vulnNot vulnNot vulnNot vulnsource
CiscoApplication Policy Infrastructure Controller (APIC) - Network Insights Base App4.2(7r), 5.2(3g)FixFixNot vulnsource
CiscoApplication Policy Infrastructure Controller Enterprise Module (APIC-EM)AllNot vulnNot vulnNot vulnsource
CiscoASR 5000 Series RoutersNot vulnNot vulnNot vulnNot vulnsource
CiscoAutomated Subsea Tuning2.1.0FixFixNot vulnsource
CiscoBroadcloud CallingInvestigationsource
CiscoBroadWorks2021.11_1.162, ap381882FixFixNot vulnsource
CiscoBusiness 100 and 200 Series Access PointsAllNot vulnNot vulnNot vulnsource
CiscoBusiness 220 Series Smart SwitchesAllNot vulnNot vulnNot vulnsource
CiscoBusiness 250 Series Smart SwitchesAllNot vulnNot vulnNot vulnsource
CiscoBusiness 350 Series Managed SwitchesAllNot vulnNot vulnNot vulnsource
CiscoBusiness DashboardAllNot vulnNot vulnNot vulnsource
CiscoBusiness Process Automation3.0.000.115, 3.1.000.044, 3.2.000.009FixFixNot vulnsource
CiscoBusiness WirelessAllNot vulnNot vulnNot vulnsource
CiscoCall Studio11.6(2), 12.0(1), 12.5(1), 12.6(1)FixFixNot vulnsource
CiscoCatalyst 9100 Series Access PointsAllNot vulnNot vulnNot vulnsource
CiscoCatalyst 9800 Series Wireless ControllersNot vulnNot vulnNot vulnNot vulnsource
Cisco220 Series Smart Plus SwitchesAllNot vulnNot vulnNot vulnsource
Cisco250 Series Smart SwitchesAllNot vulnNot vulnNot vulnsource
Cisco350 Series Series Managed SwitchesAllNot vulnNot vulnNot vulnsource
Cisco5000 Series Enterprise Network Compute system (ENCS)AllNot vulnNot vulnNot vulnsource
Cisco550 Series Stackable Managed SwitchesAllNot vulnNot vulnNot vulnsource
CiscoCloud Connect12.6(1)FixFixNot vulnsource
CiscoCloud Email SecurityNot vulnNot vulnNot vulnNot vulnsource
CiscoCloud Services Platform 2100AllNot vulnNot vulnNot vulnNot vulnsource
CiscoCloud Services Platform 5000 SeriesAllNot vulnNot vulnNot vulnNot vulnsource
CiscoCloudCenter4.10.0.16FixFixNot vulnFixes should be available from 23 Dec 2021source
CiscoCloudCenter Action OrchestratorNot vulnNot vulnNot vulnNot vulnsource
CiscoCloudCenter Cost Optimizer5.5.2FixFixsource
CiscoCloudCenter Suite Admin5.3.1FixFixsource
CiscoCloudCenter Workload Manager5.5.2Fixsource
CiscoCloudlockAllFixFixNot vulnsource
CiscoCloudlock for GovernmentAllFixFixNot vulnsource
CiscoCognitive IntelligenceNot vulnNot vulnNot vulnNot vulnsource
CiscoCollaboration Experience Service (CES)AllNot vulnNot vulnNot vulnsource
CiscoCollaboration Experience Service Management (CESM)AllNot vulnNot vulnNot vulnsource
CiscoCommon Services Platform Collector (CSPC)2.10.0, 2.9.1.3FixFixNot vulnsource
CiscoComputer Telephony Integration Object Server (CTIOS)Vulnerablesource
CiscoConfDNot vulnNot vulnNot vulnNot vulnsource
CiscoConnected Grid Device ManagerNot vulnNot vulnNot vulnNot vulnsource
CiscoConnected Mobile Experiences (CMX)10.6.3-70, 10.6.3-105, 10.6.2-89, 10.4.1FixFixNot vulnsource
CiscoConnectivityNot vulnsource
CiscoContact Center Domain Manager (CCDM)12.5(1) ES6, 12.6(1) ES3FixFixNot vulnsource
CiscoContact Center Management Portal (CCMP)12.5(1) ES6, 12.6(1) ES3FixFixNot vulnsource
CiscoContainer PlatformNot vulnNot vulnNot vulnNot vulnsource
CiscoContent Security Management Appliance (SMA)Not vulnNot vulnNot vulnNot vulnsource
CiscoCrosswork Change AutomationAllNot vulnNot vulnNot vulnsource
CiscoCrosswork CloudAllNot vulnNot vulnNot vulnsource
CiscoCrosswork Data Gateway2.0.2, 3.0.1FixFixNot vulnsource
CiscoCrosswork Health InsightsAllNot vulnNot vulnNot vulnsource
CiscoCrosswork Network Controller2.0.1, 3.0.1FixFixNot vulnsource
CiscoCrosswork Optimization Engine2.0.1, 3.0.1FixFixNot vulnsource
CiscoCrosswork Platform Infrastructure4.0.1, 4.1.1FixFixNot vulnsource
CiscoCrosswork Situation Manager8.0.0.8FixFixNot vulnsource
CiscoCrosswork Service HealthAllNot vulnNot vulnNot vulnsource
CiscoCrosswork Zero Touch Provisioning (ZTP)2.0.1, 3.0.1FixFixNot vulnsource
CiscoCX CloudAllFixFixNot vulnsource
CiscoCX Cloud Agent Software1.12.2FixFixNot vulnsource
CiscoCyber Vision Sensor Management Extension4.0.3FixFixNot vulnsource
CiscoData Center Network Manager (DCNM)12.0(2d), 11.5(3), 11.5(2), 11.5(1), 11.4(1), 11.3(1)VulnerableVulnerableNot vulnsource
CiscoDefense OrchestratorNot vulnNot vulnNot vulnNot vulnsource
CiscoDNA AssuranceInvestigationsource
CiscoDNA Center2.2.2.8, 2.1.2.8, 2.2.3.4FixFixNot vulnsource
CiscoDNA Spaces2.5, 2.8.2, 2.11.0, 2.13.3Not vulnFixsource
CiscoDNA Spaces Connectorv2.0.588, v2.2.12FixFixNot vulnsource
CiscoDuoNot vulnFixsource
Ciscoduo network gateway (on-prem/self-hosted)Investigation
CiscoDUO network gateway (on-prem/self-hosted)Investigation
CiscoDuo Security for GovernmentAllFixFixNot vulnsource
CiscoElastic Services Controller (ESC)Not vulnNot vulnNot vulnNot vulnsource
CiscoEmail Security Appliance (ESA)Not vulnNot vulnNot vulnNot vulnsource
CiscoEmergency Responder11.5(4)SU9, 11.5(4)SU10FixFixNot vulnsource
CiscoEnterprise Chat and Email12.0(1), 12.5(1), 12.6(1)FixFixNot vulnsource
CiscoEnterprise NFV Infrastructure Software (NFVIS)Not vulnNot vulnNot vulnNot vulnsource
CiscoeSIM FlexAllFixFixNot vulnsource
CiscoEvolved Programmable Network Manager5.1.3.1FixFixNot vulnsource
CiscoEvolved Programmable Network Manager< 5.0.2.1, < 4.1.1.1VulnerableVulnerableNot vulnFix should be available from 13 Jan 2022source
CiscoExony Virtualized Interaction Manager (VIM)Investigationsource
CiscoExpressway SeriesNot vulnNot vulnNot vulnNot vulnsource
CiscoExtensible Network Controller (XNC)Not vulnNot vulnNot vulnNot vulnsource
CiscoFinesse< 12.6(1)ES03Vulnerablesource
CiscoFirepower 4100 SeriesNot vulnNot vulnNot vulnNot vulnsource
CiscoFirepower 9300 Security AppliancesInvestigationsource
CiscoFirepower Management CenterNot vulnNot vulnNot vulnNot vulnsource
CiscoFirepower Threat Defense (FTD) managed by FDM6.2.3 hotfix, 6.4.0 hotfix, 6.6.5 hotfix, 6.7.0 hotfix, 7.0.1 hotfix, 7.1.0 hotfixFixsource
CiscoGeneral Cisco DisclaimerCisco is updating their advisory three times a day, please keep their website in your watchlist. We will try to update accordingly
CiscoGGSN Gateway GPRS Support NodeNot vulnNot vulnNot vulnNot vulnsource
CiscoHosted Collaboration Mediation FulfillmentNot vulnNot vulnNot vulnNot vulnsource
CiscoHyperFlex SystemNot vulnNot vulnNot vulnNot vulnsource
CiscoIdentity Services Engine (ISE)2.4 hotfix, 2.6 hotfix, 2.7 hotfix, 3.0 hotfix, 3.1 hotfixFixFix expected on Dec 17thsource
CiscoIntegrated Management Controller (IMC) Supervisor2.3.2.1Fixsource
CiscoIntersightInvestigationsource
CiscoIntersight Virtual ApplianceVulnerablesource
CiscoIOS and IOS XE SoftwareNot vulnNot vulnNot vulnNot vulnsource
CiscoIOS XR SoftwareNot vulnNot vulnNot vulnNot vulnsource
CiscoIoT Field Network Director (formerly Connected Grid Network Management System)InvestigationVulnerability in Apache Log4j Library Affecting Cisco Products: December 2021
CiscoIoT Field Network Director (formerly Cisco Connected Grid Network Management System)Not vulnNot vulnNot vulnNot vulnsource
CiscoIoT Operations DashboardInvestigationsource
CiscoIOx Fog DirectorVulnerablesource
CiscoIP Services Gateway (IPSG)Not vulnNot vulnNot vulnNot vulnsource
CiscoJabber GuestAllNot vulnNot vulnNot vulnNot vulnsource
CiscoKinetic for CitiesInvestigationsource
CiscoManaged Services Accelerator (MSX) Network Access Control ServiceInvestigationsource
CiscoMDS 9000 Series Multilayer SwitchesNot vulnNot vulnNot vulnNot vulnsource
CiscoMeeting ServerNot vulnNot vulnNot vulnNot vulnsource
CiscoMeraki GONot vulnNot vulnNot vulnNot vulnsource
CiscoMeraki MRNot vulnNot vulnNot vulnNot vulnsource
CiscoMeraki MSNot vulnNot vulnNot vulnNot vulnsource
CiscoMeraki MTNot vulnNot vulnNot vulnNot vulnsource
CiscoMeraki MVNot vulnNot vulnNot vulnNot vulnsource
CiscoMeraki MXNot vulnNot vulnNot vulnNot vulnsource
CiscoMeraki System ManagerNot vulnNot vulnNot vulnNot vulnsource
CiscoMeraki Z-SeriesNot vulnNot vulnNot vulnNot vulnsource
CiscoMME Mobility Management EntityNot vulnNot vulnNot vulnNot vulnsource
CiscoMobility Services EngineNot vulnNot vulnNot vulnNot vulnsource
CiscoMobility Unified Reporting and Analytics SystemNot vulnNot vulnNot vulnNot vulnsource
CiscoModeling LabsNot vulnNot vulnNot vulnNot vulnsource
CiscoNetwork Assessment (CNA) ToolInvestigationsource
CiscoNetwork Assurance EngineVulnerablesource
CiscoNetwork Convergence System 2000 SeriesNot vulnNot vulnNot vulnNot vulnsource
CiscoNetwork PlannerInvestigationsource
CiscoNetwork Services Orchestrator (NSO)< nso-5.3.5.1, nso-5.4.5.2, nso-5.5.4.1, nso-5.6.3.1VulnerableFixes expected 17-Decsource
CiscoNexus 3000 Series SwitchesNot vulnNot vulnNot vulnNot vulnsource
CiscoNexus 5500 Platform SwitchesNot vulnNot vulnNot vulnNot vulnsource
CiscoNexus 5600 Platform SwitchesNot vulnNot vulnNot vulnNot vulnsource
CiscoNexus 6000 Series SwitchesNot vulnNot vulnNot vulnNot vulnsource
CiscoNexus 7000 Series SwitchesNot vulnNot vulnNot vulnNot vulnsource
CiscoNexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) modeNot vulnNot vulnNot vulnNot vulnsource
CiscoNexus 9000 Series Switches in standalone NX-OS modeNot vulnNot vulnNot vulnNot vulnsource
CiscoNexus Dashboard (formerly Application Services Engine)InvestigationVulnerability in Apache Log4j Library Affecting Cisco Products: December 2021
CiscoNexus Dashboard (formerly Cisco Application Services Engine)<2.1.2VulnerableFixes expected 7-Jan-2022source
CiscoNexus Data BrokerNot vulnNot vulnNot vulnNot vulnsource
CiscoNexus InsightsInvestigationsource
CiscoOptical Network PlannerInvestigationsource
CiscoPackaged Contact Center EnterpriseVulnerablesource
CiscoPaging ServerInvestigationsource
CiscoPaging Server (InformaCast)Investigationsource
CiscoPDSN/HA Packet Data Serving Node and Home AgentNot vulnNot vulnNot vulnNot vulnsource
CiscoPGW Packet Data Network GatewayNot vulnNot vulnNot vulnNot vulnsource
CiscoPolicy SuiteNot vulnNot vulnNot vulnNot vulnsource
CiscoPrime Access RegistrarNot vulnNot vulnNot vulnNot vulnsource
CiscoPrime Cable ProvisioningNot vulnNot vulnNot vulnNot vulnsource
CiscoPrime Central for Service ProvidersInvestigationsource
CiscoPrime Collaboration AssuranceNot vulnNot vulnNot vulnNot vulnsource
CiscoPrime Collaboration DeploymentNot vulnNot vulnNot vulnNot vulnsource
CiscoPrime Collaboration ManagerInvestigationsource
CiscoPrime Collaboration ProvisioningNot vulnNot vulnNot vulnNot vulnsource
CiscoPrime InfrastructureInvestigationsource
CiscoPrime IP ExpressNot vulnNot vulnNot vulnNot vulnsource
CiscoPrime License ManagerNot vulnNot vulnNot vulnNot vulnsource
CiscoPrime NetworkNot vulnNot vulnNot vulnNot vulnsource
CiscoPrime Network RegistrarNot vulnNot vulnNot vulnNot vulnsource
CiscoPrime Optical for Service ProvidersNot vulnNot vulnNot vulnNot vulnsource
CiscoPrime Performance ManagerNot vulnNot vulnNot vulnNot vulnsource
CiscoPrime ProvisioningNot vulnNot vulnNot vulnNot vulnsource
CiscoPrime Service CatalogInvestigationsource
CiscoRegistered Envelope ServiceNot vulnNot vulnNot vulnNot vulnsource
CiscoSD-WAN vEdge 1000 Series RoutersNot vulnNot vulnNot vulnNot vulnsource
CiscoSD-WAN vEdge 2000 Series RoutersNot vulnNot vulnNot vulnNot vulnsource
CiscoSD-WAN vEdge 5000 Series RoutersNot vulnNot vulnNot vulnNot vulnsource
CiscoSD-WAN vEdge Cloud Router PlatformNot vulnNot vulnNot vulnNot vulnsource
CiscoSD-WAN vManageVulnerablesource
CiscoSecure Network Analytics (SNA), formerly StealthwatchInvestigationsource
CiscoSecurity ManagerNot vulnNot vulnNot vulnNot vulnsource
CiscoSmart Software Manager On-PremNot vulnNot vulnNot vulnNot vulnsource
CiscoSocialMinerAllNot vulnNot vulnNot vulnNot vulnsource
CiscoSystem Architecture Evolution Gateway (SAEGW)Not vulnNot vulnNot vulnNot vulnsource
CiscoTelePresence Management SuiteNot vulnNot vulnNot vulnNot vulnsource
CiscoTelePresence Video Communication Server (VCS)Not vulnNot vulnNot vulnNot vulnsource
CiscoTetration AnalyticsAllNot vulnNot vulnNot vulnNot vulnsource
CiscoUCS C-Series Rack Servers - Integrated Management ControllerNot vulnNot vulnNot vulnNot vulnsource
CiscoUCS Central Software2.3.2.1Fixsource
CiscoUCS Director6.8.2.0Fixsource
CiscoUCS ManagerNot vulnNot vulnNot vulnNot vulnsource
CiscoUCS Performance ManagerInvestigationsource
CiscoUltra Packet CoreNot vulnNot vulnNot vulnNot vulnsource
CiscoUmbrellaInvestigationsource
CiscoUnified Attendant Console AdvancedNot vulnNot vulnNot vulnNot vulnsource
CiscoUnified Attendant Console Business EditionNot vulnNot vulnNot vulnNot vulnsource
CiscoUnified Attendant Console Department EditionNot vulnNot vulnNot vulnNot vulnsource
CiscoUnified Attendant Console Enterprise EditionNot vulnNot vulnNot vulnNot vulnsource
CiscoUnified Attendant Console Premium EditionNot vulnNot vulnNot vulnNot vulnsource
CiscoUnified Communications Domain ManagerNot vulnNot vulnNot vulnNot vulnsource
CiscoUnified Communications Manager / Cisco Unified Communications Manager Session Management EditionVulnerablesource
CiscoUnified Communications Manager CloudVulnerablesource
CiscoUnified Communications Manager IM & Presence Service (formerly CUPS)Vulnerablesource
CiscoUnified Contact Center EnterpriseVulnerablesource
CiscoUnified Contact Center Enterprise - Live Data serverVulnerablesource
CiscoUnified Contact Center ExpressVulnerablesource
CiscoUnified Customer Voice PortalNot vulnNot vulnNot vulnNot vulnsource
CiscoUnified Intelligence CenterNot vulnNot vulnNot vulnNot vulnsource
CiscoUnified Intelligent Contact Management EnterpriseVulnerablesource
CiscoUnified SIP Proxy SoftwareVulnerablesource
CiscoUnity ConnectionVulnerablesource
CiscoUnity ExpressNot vulnNot vulnNot vulnNot vulnsource
CiscoVideo Surveillance Media ServerNot vulnNot vulnNot vulnNot vulnsource
CiscoVideo Surveillance Operations Manager<7.14.4VulnerableFixes expected 16-Dec-2021source
CiscoVirtual Topology System - Virtual Topology Controller (VTC) VMInvestigationsource
CiscoVirtualized Voice BrowserInvestigationsource
CiscoVision Dynamic Signage DirectorNot vulnNot vulnNot vulnNot vulnsource
CiscoWAN Automation Engine (WAE)Vulnerablesource
CiscoWeb Security Appliance (WSA)Not vulnNot vulnNot vulnNot vulnsource
CiscoWebex AppNot vulnNot vulnNot vulnNot vulnsource
CiscoWebex Cloud-Connected UC (CCUC)Vulnerablesource
CiscoWebex Meetings ServerCWMS-3.0MR4SP2, CWMS-4.0MR4SP2,CWMS-3.0MR4SP3, CWMS-4.0MR4SP3FixFixes expected 14-Dec-2021source
CiscoWebex Room PhoneNot vulnNot vulnNot vulnNot vulnsource
CiscoWebex TeamsInvestigationVulnerability in Apache Log4j Library Affecting Cisco Products: December 2021
CiscoWide Area Application Services (WAAS)AllNot vulnNot vulnNot vulnNot vulnsource
CiscoWireless LAN ControllerNot vulnNot vulnNot vulnNot vulnsource
CitrixADC (NetScaler ADC) and Gateway (NetScaler Gateway)All PlatformsNot vulnNot vulnNot vulnNot vulnCitrix continues to investigate any potential impact on Citrix-managed cloud services. If, as the investigation continues, any Citrix-managed services are found to be affected by this issue, Citrix will take immediate action to remediate the problem. Customers using Citrix-managed cloud services do not need to take any action.Citrix Statement
CitrixAnalyticsInvestigationsource
CitrixApplication Delivery Management (NetScaler MAS)AllNot vulnNot vulnNot vulnNot vulnsource
CitrixCloud ConnectorNot vulnNot vulnNot vulnNot vulnsource
CitrixConnector Appliance for Cloud ServicesNot vulnNot vulnNot vulnNot vulnsource
CitrixContent Collaboration (ShareFile Integration)Not vulnNot vulnNot vulnNot vulnsource
CitrixContent Collaboration (ShareFile Integration) โ€“ Files for Windows, Files for Mac, Files for OutlookNot vulnNot vulnNot vulnNot vulnCitrix continues to investigate any potential impact on Citrix-managed cloud services. If, as the investigation continues, any Citrix-managed services are found to be affected by this issue, Citrix will take immediate action to remediate the problem. Customers using Citrix-managed cloud services do not need to take any action.Citrix Statement
CitrixEndpoint Management ( XenMobile Server)Not vulnFixFor CVE-2021-44228 and CVE-2021-45046: Impactedโ€“Customers are advised to apply the latest CEM rolling patch updates listed below as soon as possible to reduce the risk of exploitation. https://support.citrix.com/article/CTX335763 XenMobile Server 10.14 RP2; https://support.citrix.com/article/CTX335753 XenMobile Server 10.13 RP5; and https://support.citrix.com/article/CTX335785 XenMobile Server 10.12 RP10. Note: Customers who have upgraded their XenMobile Server to the updated versions are recommended not to apply the responder policy mentioned in the blog listed below to the Citrix ADC vserver in front of the XenMobile Server as it may impact the enrollment of Android devices. For CVE-2021-45105: Investigation in progress.Citrix Statement
CitrixEndpoint Management (XenMobile Server)10.12 RP10, 10.13 RP5 and 10.14 RP2Not vulnFixFixInvestigationsource
CitrixFiles for MacNot vulnNot vulnNot vulnNot vulnsource
CitrixFiles for OutlookNot vulnNot vulnNot vulnNot vulnsource
CitrixFiles for WindowsNot vulnNot vulnNot vulnNot vulnsource
CitrixHypervisor (XenServer)Not vulnsource
CitrixLicense ServerNot vulnNot vulnNot vulnNot vulnsource
CitrixNetScaler ADCAllNot vulnNot vulnNot vulnNot vulnsource
CitrixNetScaler GatewayAllNot vulnNot vulnNot vulnNot vulnsource
CitrixSD-WANAllNot vulnNot vulnNot vulnNot vulnsource
CitrixSharefileNot vulnNot vulnNot vulnNot vulnsource
CitrixShareFile Storage Zones ControllerNot vulnNot vulnNot vulnNot vulnCitrix continues to investigate any potential impact on Citrix-managed cloud services. If, as the investigation continues, any Citrix-managed services are found to be affected by this issue, Citrix will take immediate action to remediate the problem. Customers using Citrix-managed cloud services do not need to take any action.Citrix Statement
CitrixVirtual Apps and Desktops (XenApp & XenDesktop)Linux VDA 2112Not vulnFixInvestigationImpacted โ€“ Linux VDA (non-LTSR versions only), Not vulnerable: App Layering, Delivery Controller, Director, FAS, HDX, Profile Management, PVS, Session Recording, Storefront, Studio, Windows VDA, WEMsource
CitrixWorkspaceNot vulnNot vulnNot vulnNot vulnsource
CitrixWorkspace AppAllNot vulnNot vulnNot vulnNot vulnsource
ClarisAllClaris Article
ClavisterEasyAccess<= 4.1.2Not vulnFixsource
ClavisterInCenter<= 1.68.03, 2.0.0 and 2.1.0Not vulnFixsource
ClavisterInControlNot vulnNot vulnNot vulnNot vulnsource
ClavisterNetShieldNot vulnNot vulnNot vulnNot vulnsource
ClavisterNetWallNot vulnNot vulnNot vulnNot vulnsource
ClavisterOneConnectNot vulnNot vulnNot vulnNot vulnsource
ClouderaAM2CM ToolNot vulnNot vulnNot vulnNot vulnsource
ClouderaAmbariOnly versions 2.x, 1.xVulnerablesource
ClouderaArcadia EnterpriseOnly version 7.1.xVulnerablesource
ClouderaCDH, HDP, and HDFOnly version 6.xVulnerablesource
ClouderaCDP Operational Database (COD)Not vulnNot vulnNot vulnNot vulnsource
ClouderaCDP Private Cloud BaseOnly version 7.xVulnerablesource
ClouderaCDS 3 Powered by Apache SparkAllVulnerablesource
ClouderaCDS 3.2 for GPUsAllVulnerablesource
ClouderaCybersecurity PlatformAllVulnerablesource
ClouderaData Analytics Studio (DAS)Investigationsource
ClouderaData CatalogNot vulnNot vulnNot vulnNot vulnsource
ClouderaData Engineering (CDE)AllVulnerablesource
ClouderaData Engineering (CDE)Vulnerablesource
ClouderaData Flow (CFM)Vulnerablesource
ClouderaData Lifecycle Manager (DLM)Not vulnNot vulnNot vulnNot vulnsource
ClouderaData Science Workbench (CDSW)Only versions 2.x, 3.xVulnerablesource
ClouderaData Steward Studio (DSS)AllVulnerablesource
ClouderaData Visualization (CDV)Vulnerablesource
ClouderaData Warehouse (CDW)AllVulnerablesource
ClouderaData Warehouse (CDW)Vulnerablesource
ClouderaDataFlow (CDF)Vulnerablesource
ClouderaEdge Management (CEM)AllVulnerablesource
ClouderaEnterpriseOnly version 6.xVulnerablesource
ClouderaFlow Management (CFM)AllVulnerablesource
ClouderaHortonworks Data Flow (HDF)Not vulnNot vulnNot vulnNot vulnsource
ClouderaHortonworks Data Platform (HDP)Only versions 7.1.x, 2.7.x, 2.6.xVulnerablesource
ClouderaHortonworks DataPlane PlatformNot vulnNot vulnNot vulnNot vulnsource
ClouderaMachine Learning (CML)AllVulnerablesource
ClouderaMachine Learning (CML)Vulnerablesource
ClouderaManagement ConsoleAllVulnerablesource
ClouderaManagement Console for CDP Public CloudNot vulnNot vulnNot vulnNot vulnsource
ClouderaManager (Including Backup Disaster Recovery (BDR) and Replication Manager)AllVulnerablesource
ClouderaManager (Including Backup Disaster Recovery (BDR) and Replication Manager)Only versions 7.0.x, 7.1.x, 7.2.xVulnerablesource
ClouderaManager (Including Backup Disaster Recovery (BDR))Not vulnNot vulnNot vulnNot vulnsource
ClouderaReplication ManagerVulnerablesource
ClouderaRuntime (including Data Hub and all Data Hub templates)Only versions 7.0.x, 7.1.x, 7.2.xVulnerablesource
ClouderaSmartSenseInvestigationsource
ClouderaStream Processing (CSP)AllVulnerablesource
ClouderaStreaming Analytics (CSA)Not vulnNot vulnNot vulnNot vulnsource
ClouderaStreaming Analytics (CSA)Vulnerablesource
ClouderaWorkload ManagerNot vulnNot vulnNot vulnNot vulnsource
ClouderaWorkload XMAllVulnerablesource
ClouderaWorkload XM (SaaS)Not vulnNot vulnNot vulnNot vulnsource
CloudFlareAllCloudFlare Blog Post
Cloudian HyperStoreAllCloudian Article
CloudoguEcosystemAllNot vulnFixCloudogu Community
CloudoguSCM-ManagerNot vulnNot vulnNot vulnNot vulnSCM-Manager Blog
CloudronAllCloudron Forum
CloverAllClover Article
Cockroach LabsCockroachDB-Not vulnNot vulnNot vulnNot vulnsource
Code42App8.8.1Not vulnFixCode42 Release Notification
Code42Crashplan8.8, possibly prior versionsNot vulnFixI think, they don't specify in the notice, but we know that they released an updated Crashplan client. Possibly prior versions affected.Code42 Release Notification
CodeBeamerAllCodeBeamer Link
CODESYSAllAllNot vulnNot vulnNot vulnNot vulnsource
CohesityAllCohesity Support Link
CommvaultCloud Apps & Oracle & MS-SQLAll supported versionsNot vulnFixsource
CompumaticaCompuMail GatewayAllNot vulnNot vulnNot vulnNot vulnsource
CompumaticaCompuwallAllNot vulnNot vulnNot vulnNot vulnsource
CompumaticaCryptoGuardAllNot vulnNot vulnNot vulnNot vulnsource
CompumaticaMagiCtwinAllNot vulnNot vulnNot vulnNot vulnsource
CompumaticaMASCAllNot vulnNot vulnNot vulnNot vulnsource
ConcourseAllNot vulnNot vulnNot vulnNot vulnConcourse Community Discussion
ConcreteCMS.comAllConcreteCMS.com Link
ConfluentCloudNot vulnFixserver-side fixsource
ConfluentCommunity PlatformNot vulnNot vulnNot vulnNot vulnsource
ConfluentCommunity/Standalone Package of ksqlDBNot vulnNot vulnNot vulnNot vulnNo exploitable conditions found, working on package without log4j2source
ConfluentConnectorssee linkNot vulnFixList of vulnerable connectors available at Confluentsource
ConfluentElasticSearch Sink Connector<11.1.7Not vulnFixDecember 2021 Log4j Vulnerabilities Advisory
Confluentfor Kubernetes2.1.0-1 and 2.2.0-1Not vulnFixOnly applicable to confluent-init-containersource
ConfluentGoogle DataProc Sink Connector<1.1.5Not vulnFixDecember 2021 Log4j Vulnerabilities Advisory
ConfluentHDFS 2 Sink Connector<10.1.3Not vulnFixDecember 2021 Log4j Vulnerabilities Advisory
ConfluentHDFS 3 Sink Connector<1.1.8VulnerableDecember 2021 Log4j Vulnerabilities Advisory
ConfluentKafka ConnectorsNot vulnNot vulnNot vulnNot vulnDecember 2021 Log4j Vulnerabilities Advisory
ConfluentPlatform7.0.1Not vulnFixsource
ConfluentSplunk Sink Connector<2.05Not vulnFixDecember 2021 Log4j Vulnerabilities Advisory
ConfluentVMWare Tanzu GemFire Sink Connector<1.0.8Not vulnFixDecember 2021 Log4j Vulnerabilities Advisory
Connect2idserver< 12.5.1Not vulnFixsource
ConnectwiseGlobal search capability of Manage CloudWorkaroundsource
ConnectwiseManage on-premise's Global SearchWorkaroundsource
ConnectwiseMarketplaceWorkaroundsource
ConnectwisePerchNot vulnFixsource
ConnectwiseStratoZenWorkaroundUrgent action for self-hosted versionssource
ContrastHosted SaaS EnviromentsAllNot vulnFixsource
ContrastJava AgentAllNot vulnNot vulnNot vulnNot vulnsource
ContrastOn-premises (EOP) EnvironmentsAllNot vulnFixsource
ContrastScanAllNot vulnFixsource
ContrastSecurityAllContrastSecurity Article
ControlUpAllAllNot vulnFixsource
CopadataZenon product familyAllNot vulnNot vulnNot vulnNot vulnsource
CoralogixAllNot vulnFixsource
CouchbaseElasticSearch connector< 4.3.3 & < 4.2.13Not vulnFixsource
CoveoOn-Premises Crawling ModuleNot vulnNot vulnNot vulnNot vulnsource
CoveoPlatform (hosted services)Not vulnNot vulnNot vulnNot vulnsource
cPanelAllWorkaroundsource
CradlepointAllCradlepoint
CrestronAllNot vulnNot vulnNot vulnNot vulnCrestron Advisory
CrushFTPAllCrushFTP Link
Cryptshare.NET APIAllNot vulnNot vulnNot vulnNot vulnsource
Cryptsharefor NotesAllNot vulnNot vulnNot vulnNot vulnsource
Cryptsharefor NTA 7516AllNot vulnNot vulnNot vulnNot vulnsource
Cryptsharefor OutlookAllNot vulnNot vulnNot vulnNot vulnsource
CryptshareJava APIAllNot vulnNot vulnNot vulnNot vulnsource
CryptshareRobotAllNot vulnNot vulnNot vulnNot vulnsource
CryptshareServerAllNot vulnNot vulnNot vulnNot vulnsource
CyberarkCloud Entitlements ManagerNot vulnsource
CyberarkEndpoint Privilege Manager (EPM) - AgentsNot vulnsource
CyberarkEndpoint Privilege Manager (EPM) - EPM Server (On-Premise)Not vulnsource
CyberarkEndpoint Privilege Manager (EPM) - Service (SaaS)Not vulnsource
CyberarkHTML5 GatewayNot vulnsource
CyberarkIdentity - Mobile AppNot vulnNot vulnNot vulnNot vulnsource
CyberarkIdentity - On-Premise ComponentsNot vulnNot vulnNot vulnNot vulnsource
CyberarkIdentity - Secure Web Sessions (SWS)Not vulnFixsource
CyberarkIdentity - Service (SaaS)Not vulnNot vulnNot vulnNot vulnsource
CyberarkLegacy Sensitive Information Management (SIM)Not vulnNot vulnNot vulnNot vulnsource
CyberarkMarketplace components - Certified and Trusted Marketplace ComponentsNot vulnNot vulnNot vulnNot vulnsource
CyberarkMarketplace components - CPM PluginsNot vulnNot vulnNot vulnNot vulnsource
CyberarkMarketplace components - PSM Connection ComponentsNot vulnNot vulnNot vulnNot vulnsource
CyberarkOn-Demand Privileges Manager (OPM)Not vulnsource
CyberarkPAS Self Hosted (Vault, PVWA, CPM, PSM, PSMP)Not vulnsource
CyberarkPrivilege Cloud - On-Premise ComponentsNot vulnsource
CyberarkPrivilege Cloud - Service (SaaS)Not vulnFixMitigation applied. No further action required by customerssource
CyberarkPrivileged Threat Analytics (PTA)Not vulnWorkaroundsource workaround
CyberarkRemote Access (Alero) - ConnectorNot vulnFixsource
CyberarkRemote Access (Alero) - Mobile AppNot vulnNot vulnNot vulnNot vulnsource
CyberarkRemote Access (Alero) - Service (SaaS)Not vulnFixMitigation applied. No further action required by customerssource
CyberarkSecrets Manager Conjur EnterpriseNot vulnNot vulnNot vulnNot vulnsource
CyberarkSecrets Manager Credential ProvidersNot vulnNot vulnNot vulnNot vulnsource
CybereasonAll Cybereason productsNot vulnNot vulnNot vulnNot vulnsource
CyberResAllCyberRes Community Link
Cydar MedicalEV systemNot Vulnsource