List of software (un)affected by the log4shell CVEs

June 15, 2022 · View on GitHub

About this list

0-9 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

M

SupplierProductVersion (see Status)Status CVE-2021-4104Status CVE-2021-44228Status CVE-2021-45046Status CVE-2021-45105NotesLinks
MMM GroupControl software of all MMM serieslink
MMM GroupRUMED360 Cycles, RUMED360 Cycles View, RUMED360 Sicon, RUMED360 ISA-Serverlink
Mitsubishi Electric CorporationCC-Link IE TSN<=1.02CVulnerableProduct number: SW1DNN-GN610SRC-Mlink
Mitsubishi Electric CorporationCC-Link IE TSNFixProduct number: SW1DNN-GN610SRC-Mlink
Macrium SoftwareAllNot vulnNot vulnNot vulnNot vulnsource
MailcowSolr Docker< 1.8Not vulnFixsource
MailStoreAllAllNot vulnNot vulnNot vulnNot vulnsource
MaltegoAllMaltego Response to Logj4
ManageEngineADAudit PlusNot vulnWorkaroundWorkaroundWorkaroundsource
ManageEngineADManager PlusNot vulnWorkaroundWorkaroundWorkaroundsource
ManageEngineDesktop Central10.1.2127.20FixNot vulnNot vulnNot vulnsource
ManageEngineEventLog AnalyzerNot vulnWorkaroundWorkaroundWorkaroundsource
ManageEngineServicedesk Plus11305 and belowVulnerableManage Engine Advisory
ManageEngine ZohoADAudit PlusOn-PremManageEngine Vulnerability Impact
ManageEngine ZohoADManager PlusOn-PremManageEngine Vulnerability Impact
ManageEngine ZohoADSelfService PlusNot vulnNot vulnNot vulnNot vulnManageEngine Vulnerability Impact
ManageEngine ZohoAllManage Engine Link
ManageEngine ZohoAnalytics PlusOn-PremManageEngine Vulnerability Impact
ManageEngine ZohoCloud Security PlusOn-PremManageEngine Vulnerability Impact
ManageEngine ZohoDataSecurity PlusOn-PremManageEngine Vulnerability Impact
ManageEngine ZohoEventLog AnalyzerOn-PremManageEngine Vulnerability Impact
ManageEngine ZohoExchange Reporter PlusOn-PremManageEngine Vulnerability Impact
ManageEngine ZohoLog360On-PremManageEngine Vulnerability Impact
ManageEngine ZohoLog360 UEBAOn-PremManageEngine Vulnerability Impact
ManageEngine ZohoM365 Manager PlusOn-PremManageEngine Vulnerability Impact
ManageEngine ZohoM365 Security PlusOn-PremManageEngine Vulnerability Impact
ManageEngine ZohoRecoveryManager PlusOn-PremManageEngine Vulnerability Impact
MariaDBAllMariaDB Statement
MathworksAll MathWorks general release desktop or server productsNot vulnNot vulnNot vulnNot vulnMathWorks statement regarding CVE-2021-44228
MathworksMATLABAllNot vulnsource
MathWorks MatlabAllMathWorks Matlab Statement
MatillionAllMatillion Security Advisory
MatomoAllMatomo Statement
MattermostAllNot vulnsource
Mattermost FocalBoardAllMattermost FocalBoard Concern
McAfeeActive Response (MAR)Not vulnStandalone MAR not vulnerable, for MAR included in bundle see TIEsource
McAfeeAgent (MA)Not vulnNot vulnNot vulnNot vuln
McAfeeApplication and Change Control (MACC) for LinuxNot vulnNot vulnNot vulnNot vuln
McAfeeApplication and Change Control (MACC) for WindowsNot vulnNot vulnNot vulnNot vuln
McAfeeClient Proxy (MCP) for MacNot vulnNot vulnNot vulnNot vuln
McAfeeClient Proxy (MCP) for WindowsNot vulnNot vulnNot vulnNot vuln
McAfeeData Exchange Layer (DXL)Not vulnsource
McAfeeData Exchange Layer (DXL) ClientNot vulnNot vulnNot vulnNot vuln
McAfeeData Loss Prevention (DLP) DiscoverNot vulnNot vulnNot vulnNot vuln
McAfeeData Loss Prevention (DLP) Endpoint for MacNot vulnNot vulnNot vulnNot vuln
McAfeeData Loss Prevention (DLP) Endpoint for WindowsNot vulnNot vulnNot vulnNot vuln
McAfeeData Loss Prevention (DLP) MonitorNot vulnNot vulnNot vulnNot vuln
McAfeeData Loss Prevention (DLP) PreventNot vulnNot vulnNot vulnNot vuln
McAfeeDrive Encryption (MDE)Not vulnNot vulnNot vulnNot vuln
McAfeeEndpoint Security (ENS) for LinuxNot vulnNot vulnNot vulnNot vuln
McAfeeEndpoint Security (ENS) for MacNot vulnNot vulnNot vulnNot vuln
McAfeeEndpoint Security (ENS) for WindowsNot vulnNot vulnNot vulnNot vuln
McAfeeEnterprise Security Manager (ESM)11.xNot vulnWorkaroundsource
McAfeeePolicy Orchestrator Agent Handlers (ePO-AH)Not vulnsource
McAfeeePolicy Orchestrator Application Server (ePO)<= 5.10 CU10Not vulnsource
McAfeeePolicy Orchestrator Application Server (ePO)5.10 CU11Not vulnWorkaroundsource
McAfeeHost Intrusion Prevention (Host IPS)Not vulnNot vulnNot vulnNot vuln
McAfeeManagement of Native Encryption (MNE)Not vulnNot vulnNot vulnNot vuln
McAfeeNetwork Security Manager (NSM)Not vulnsource
McAfeeNetwork Security Platform (NSP)Not vulnsource
McAfeePolicy AuditorNot vulnNot vulnNot vulnNot vuln
McAfeeSecurity for Microsoft Exchange (MSME)Not vulnNot vulnNot vulnNot vuln
McAfeeSecurity for Microsoft SharePoint (MSMS)Not vulnNot vulnNot vulnNot vuln
McAfeeThreat Intelligence Exchange (TIE)2.2, 2.3, 3.0Not vulnWorkaroundsource
McAfeeWeb Gateway (MWG)Not vulnFixsource
MedtronicAllInvestigationMedtronic Advisory Link
MeinbergLANTIMEAllNot vulnsource
MeinbergmicroSyncAllNot vulnsource
MeltanoAllNot vulnNot vulnNot vulnNot vulnProject is written in PythonMeltano
MemuraiAllNot vulnsource
messageconceptPeopleSyncAllNot vulnNot vulnNot vulnNot vulnsource
MetabaseAll<0.41.4Not vulnFixMitigations available for earlier versionssource
Micro FocusArcSight Connectors8.2 and aboveVulnerablesource
Micro FocusArcSight ESM7.2, 7.5Vulnerablesource
Micro FocusArcSight IntelligenceAllVulnerablesource
Micro FocusArcSight Logger7.2 and aboveVulnerablesource
Micro FocusArcSight ReconAllVulnerablesource
Micro FocusArcSight Transformation HubAllVulnerablesource
Micro FocusData ProtectorAllVulnerableWorkaround only for supported versions. Earlier versions are not checked/worked on.workaround source
Micro FocusSilk Performer21.0VulnerableWorkaroundsource workaround
Micro FocusSilk Test20.0 up to 21.0.1 (included)VulnerableWorkaroundsource workaround
MicroFocusAllMicroFocus Statement
MicrosoftAzure ADNot vulnADFS itself is not vulnerable, federation providers may besource
MicrosoftAzure API GatewayNot vulnNot vulnNot vulnNot vulnMicrosoft’s Response to CVE-2021-44228 Apache Log4j 2
MicrosoftAzure App ServiceNot vulnThis product itself is not vulnerable, Microsoft provides guidance on remediation for hosted applicationssource
MicrosoftAzure Application GatewayNot vulnsource
MicrosoftAzure Data Lake Store Java< 2.3.10Not vulnNot vulnNot vulnNot vulnFix has been made to upgrade log4j-core. But this dependency has scope 'test' meaning it is not part of the final product/artifact. So there's no risk for end users here.source
MicrosoftAzure DevOpsNot vulnsource
MicrosoftAzure DevOps Server2019-2020.1VulnerableWhen Azure DevOps Server Search is configured. Uses Elasticsearch OSS 6.2.4 (vulnerable) see Elasticsearch above for mitigationsource
MicrosoftAzure Front DoorNot vulnsource
MicrosoftAzure Traffic ManagerNot vulnNot vulnNot vulnNot vulnMicrosoft’s Response to CVE-2021-44228 Apache Log4j 2
MicrosoftAzure WAFNot vulnsource
MicrosoftCosmos DB Kafka Connector1.2.1Fixsource
MicrosoftDefender for IoT10.5.2Not vulnFixsource
MicrosoftEvents Hub Extension3.3.1Fixsource
MicrosoftKafka Connect for Azure Cosmo DB< 1.2.1Not vulnFixsource
MicrosoftMinecraft Java Edition1.18.1Not vulnFixsource fix
MicrosoftTeam Foundation Server2018.2+VulnerableWhen Team Foundation Server Search is configured. Uses Elasticsearch OSS 5.4.1 (vulnerable) see Elasticsearch above for mitigationsource
MicroStrategySecure Enterprise11.1.7+ 11.2.x 11.3.xNot vulnWorkaroundWorkaround available, Update scheduled for Week 51/2021source
MIDITECAllNot vulnNot vulnNot vulnNot vulnMTZ Time uses Log4j v1.xsource
Midori GlobalAllMidori Global Statement
MikrotikAllMikrotik Statement
MilestoneVMSNot vulnNot vulnNot vulnNot vulnsource
Milestone sysAllMilestone sys Statement
MimecastAllMimecast Information
MinecraftAllMinecraft Vulnerability Message
MirantisContainer CloudAllNot vulnNot vulnNot vulnNot vulnsource
MirantisContainer RuntimeAllNot vulnNot vulnNot vulnNot vulnsource
MirantisK0sAllNot vulnNot vulnNot vulnNot vulnsource
MirantisKubernetes EngineAllNot vulnNot vulnNot vulnNot vulnsource
MirantisLensAllNot vulnNot vulnNot vulnNot vulnsource
MirantisOpenStackAllNot vulnNot vulnNot vulnNot vulnsource
MirantisSecure RegistryAllNot vulnNot vulnNot vulnNot vulnsource
MiroAllMiro Log4j Updates
MISPAllAllNot vulnNot vulnNot vulnNot vulnsource
MitelCMG SuiteAllInvestigationsource
MitelInAttendAllInvestigationsource
MitelInteraction Recording (MIR)6.3 to 6.7Not vulnFixsee SA211213-17source
MitelManagement GatewayAllNot vulnNot vulnNot vulnNot vulnsource
MitelManagement PortalAllInvestigationsource
MitelMiCollab>=7.1 to <=9.4Not vulnWorkaroundWorkaroundBelow v7.0 not vuln, https://www.mitel.com/-/media/mitel/file/pdf/support/security-advisories/log4j_micollab_remediation_details.pdf Fixsource
MitelMiContact Center EnterpriseAllNot vulnNot vulnNot vulnNot vulnsource
MitelMiContact Center BusinessAllNot vulnNot vulnNot vulnNot vulnsource
MitelMiVoice 5000AllNot vulnNot vulnNot vulnNot vulnsource
MitelMiVoice Border GatewayAllNot vulnNot vulnNot vulnNot vulnsource
MitelMiVoice BusinessAll (excluding EX)Not vulnNot vulnNot vulnNot vulnsource
MitelMiVoice Business EX and MiConfig Wizard9.2 onlyNot vulnFixsource
MitelMiVoice Call RecordingAllInvestigationsource
MitelMiVoice ConnectAllNot vulnNot vulnNot vulnNot vulnsource
MitelMiVoice MX-ONE7.4 onlyNot vulnFixsource
MitelMiVoice Office 400AllNot vulnNot vulnNot vulnNot vulnsource
MitelMobility RouterAllNot vulnNot vulnNot vulnNot vulnsource
MitelOpen Integration Gateway (OIG)AllInvestigationsource
MitelPerformance Analytics Server and ProbeAllInvestigationsource
MitelStandard Linux (MSL)AllNot vulnNot vulnNot vulnNot vulnsource
MitelVirtual ReceptionAllInvestigationsource
MitsubishiCS-141Not vulnNot vulnNot vulnNot vulnhttps://user-images.githubusercontent.com/89155495/146846042-4c923ea4-58ec-452f-94b2-6a1aa7918ece.png
MitsubishiLookUPS N002Not vulnNot vulnNot vulnNot vulnhttps://user-images.githubusercontent.com/89155495/146846042-4c923ea4-58ec-452f-94b2-6a1aa7918ece.png
MitsubishiLookUPS N003Not vulnNot vulnNot vulnNot vulnhttps://user-images.githubusercontent.com/89155495/146846042-4c923ea4-58ec-452f-94b2-6a1aa7918ece.png
MitsubishiMUCMNot vulnNot vulnNot vulnNot vulnhttps://user-images.githubusercontent.com/89155495/146846042-4c923ea4-58ec-452f-94b2-6a1aa7918ece.png
MitsubishiNetcomNot vulnNot vulnNot vulnNot vulnhttps://user-images.githubusercontent.com/89155495/146846042-4c923ea4-58ec-452f-94b2-6a1aa7918ece.png
MitsubishiNetcom 2Not vulnNot vulnNot vulnNot vulnsource
MobileIronCoreAllNot vulnFixThe mitigation instructions listed in a subsequent section removes a vulnerable Java class (JNDILookUp.class) from the affected Log4J Java library and as a result removes the ability to perform the RCE attack. The workaround needs to be applied in a maintenance window. You will not be able to access the admin portal during the procedure, however, end user devices will continue to function.source
MobileIronCore ConnectorAllNot vulnFixThe mitigation instructions listed in a subsequent section removes a vulnerable Java class (JNDILookUp.class) from the affected Log4J Java library and as a result removes the ability to perform the RCE attack. The workaround needs to be applied in a maintenance window. You will not be able to access the admin portal during the procedure, however, end user devices will continue to function.source
MobileIronReporting Database (RDB)AllNot vulnFixThe mitigation instructions listed in a subsequent section removes a vulnerable Java class (JNDILookUp.class) from the affected Log4J Java library and as a result removes the ability to perform the RCE attack. The workaround needs to be applied in a maintenance window. You will not be able to access the admin portal during the procedure, however, end user devices will continue to function.source
MobileIronSentry9.13, 9.14Not vulnFixThe mitigation instructions listed in a subsequent section removes a vulnerable Java class (JNDILookUp.class) from the affected Log4J Java library and as a result removes the ability to perform the RCE attack. The workaround needs to be applied in a maintenance window. You will not be able to access the admin portal during the procedure, however, end user devices will continue to function.source
MONARCAllAllNot vulnNot vulnNot vulnNot vulnsource
MongoDBAll other components of MongoDB Atlas (including Atlas Database, Data Lake, Charts)Not vulnNot vulnNot vulnNot vulnsource
MongoDBAtlasNot vulnNot vulnNot vulnNot vulnIncluding Atlas Database, Data Lake, Chartssource
MongoDBAtlas SearchNot vulnFixAffected and patched. No evidence of exploitation or indicators of compromise prior to the patch were discovered.source
MongoDBCommunity EditionNot vulnNot vulnNot vulnNot vulnIncluding Community Server, Cloud Manager, Community Kubernetes Operators.source
MongoDBCommunity Edition (including Community Server, Cloud Manager, Community Kubernetes Operators)Not vulnNot vulnNot vulnNot vulnsource
MongoDBDriversNot vulnNot vulnNot vulnNot vulnsource
MongoDBEnterprise AdvancedNot vulnNot vulnNot vulnNot vulnIncluding Enterprise Server, Ops Manager, Enterprise Kubernetes Operators.source
MongoDBEnterprise Advanced (including Enterprise Server, Ops Manager, Enterprise Kubernetes Operators)Not vulnNot vulnNot vulnNot vulnsource
MongoDBRealmNot vulnNot vulnNot vulnNot vulnincluding Realm Database, Sync, Functions, APIssource
MongoDBRealm (including Realm Database, Sync, Functions, APIs)Not vulnNot vulnNot vulnNot vulnsource
MongoDBToolsNot vulnNot vulnNot vulnNot vulnIncluding Compass, Database Shell, VS Code Plugin, Atlas CLI, Database Connectorssource
MongoDBTools (including Compass, Database Shell, VS Code Plugin, Atlas CLI, Database Connectors)Not vulnNot vulnNot vulnNot vulnsource
MoodleAllAllNot vulnNot vulnNot vulnNot vulnsource
MoogSoftAllMoogSoft Vulnerability Information
Motorola AvigilonAllMotorola Avigilon Technical Notification
MoxaAllAllNot vulnNot vulnNot vulnNot vulnsource
MulesoftAllThis advisory is available to customers only and has not been reviewed by CISAMulesoft Statement
MulesoftAnypoint Studio7.xNot vulnFixThis advisory is available to account holders only and has not been reviewed by CISA.Apache Log4j2 vulnerability - December 2021
MulesoftCloudhubNot vulnFixThis advisory is available to account holders only and has not been reviewed by CISA.Apache Log4j2 vulnerability - December 2021
MulesoftMule Agent6.xNot vulnFixThis advisory is available to account holders only and has not been reviewed by CISA.Apache Log4j2 vulnerability - December 2021
MulesoftMule Runtime3.x,4.xNot vulnFixThis advisory is available to account holders only and has not been reviewed by CISA.Apache Log4j2 vulnerability - December 2021