CISA Log4j (CVE-2021-44228) Affected Vendor & Software List

March 1, 2022 · View on GitHub

0-9 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Status Descriptions

StatusDescription
UnknownStatus unknown. Default choice.
AffectedReported to be affected by CVE-2021-44228.
Not AffectedReported to NOT be affected by CVE-2021-44228 and no further action necessary.
FixedPatch and/or mitigations available (see provided links).
Under InvestigationVendor investigating status.

Software List

This list has been populated using information from the following sources:

  • Kevin Beaumont
  • SwitHak
  • National Cyber Security Centre - Netherlands (NCSC-NL)

NOTE: This file is automatically generated. To submit updates, please refer to CONTRIBUTING.md.

VendorProductAffected VersionsPatched VersionsStatusVendor LinksNotesReferencesReporterLast Updated
ABBAlarmInsight CloudNot Affectedlinkcisagov2022-01-12
ABBB&R ProductsNot Affectedlinkcisagov2022-01-12
ABBRemote ServiceFixedlinkcisagov2022-01-12
AbbottAllUnknownlinkDetails are shared with customers with an active RAP subscription.cisagov2021-12-15
AbbottGLP Track SystemTrack Sample Manager (TSM), Track Workflow Manager (TWM)AffectedlinkAbbott will provide a fix for this in a future update expected in January 2022.cisagov2021-12-15
Abnormal SecurityAllNot Affectedlinkcisagov2022-01-12
Accellence TechnologiesEBÜSAllFixedlinkEBÜS itself is not vulnerable to CVE-2021-44228. Although it includes several 3rd-party software setups, which may be affected.cisagov2022-01-12
Accellence TechnologiesVimaccNot Affectedlinkcisagov2022-01-12
AccellionKiteworksv7.6 releaseFixedlinkAs a precaution, Kiteworks released a 7.6.1 Hotfix software update to address the vulnerability. This patch release adds the mitigation for CVE-2021-44228 contained in the Solr package as recommended by Apache Solr group. Specifically, it updates the Log4j library to a non-vulnerable version on CentOS 7 systems as well as adds the recommended option “$SOLR_OPTS -Dlog4j2.formatMsgNoLookups=true" to disable the possible attack vector on both CentOS 6 and CentOS 7.cisagov2021-12-16
AccruentAnalyticsFixedlinkcisagov2022-01-12
AccruentAsset EnterpriseNot Affectedlinkcisagov2022-01-12
AccruentBigCenterFixedlinkcisagov2022-01-12
AccruentEMSNot Affectedlinkcisagov2022-01-12
AccruentEvocoFixedlinkcisagov2022-01-12
AccruentExpesiteFixedlinkcisagov2022-01-12
AccruentFamis 360Fixedlinkcisagov2022-01-12
AccruentLucernexFixedlinkcisagov2022-01-12
AccruentMaintenance ConnectionNot Affectedlinkcisagov2022-01-12
AccruentMeridianFixedlinkcisagov2022-01-12
AccruentSingle Sign On (SSO, Central Auth)Not Affectedlinkcisagov2022-01-12
AccruentSiteFM3Fixedlinkcisagov2022-01-12
AccruentSiteFM4Fixedlinkcisagov2022-01-12
AccruentSiterraFixedlinkcisagov2022-01-12
AccruentTMSNot Affectedlinkcisagov2022-01-12
AccruentVxFieldNot Affectedlinkcisagov2022-01-12
AccruentVxMaintainFixedlinkcisagov2022-01-12
AccruentVxObserveFixedlinkcisagov2022-01-12
AccruentVxSustainFixedlinkcisagov2022-01-12
AcquiaAllUnknownlinkcisagov2022-01-12
AcronisBackupNot Affectedlinkcisagov2022-01-12
AcronisCyber BackupNot Affectedlinkcisagov2022-01-12
AcronisCyber FilesNot Affectedlinkcisagov2022-01-12
AcronisCyber InfrastructureNot Affectedlinkcisagov2022-01-12
AcronisCyber ProtectNot Affectedlinkcisagov2022-01-12
AcronisCyber Protection Home OfficeNot Affectedlinkcisagov2022-01-12
AcronisDeviceLock DLPNot Affectedlinkcisagov2022-01-12
AcronisFiles ConnectNot Affectedlinkcisagov2022-01-12
AcronisMassTransitNot Affectedlinkcisagov2022-01-12
AcronisSnap DeployNot Affectedlinkcisagov2022-01-12
ActiveStateAllUnknownlinkcisagov2022-01-12
Acunetix360Not Affectedlinkcisagov2022-01-12
AcunetixAgentsNot Affectedlinkcisagov2022-01-12
AcunetixApplicationNot Affectedlinkcisagov2022-01-12
AcunetixIAST - ASP.NETNot Affectedlinkcisagov2022-01-12
AcunetixIAST - NodeJSNot Affectedlinkcisagov2022-01-12
AcunetixIAST - PHPNot Affectedlinkcisagov2022-01-12
AcunetixIAST-JavaAllFixedlinkAcuSensor IAST module needs attention.cisagov2022-01-12
AdaptecAllUnknownlinkcisagov2022-01-12
AddigyAllUnknownlinkcisagov2022-01-12
AdeptiaConnect3.3, 3.4, 3.5Fixedlinkcisagov2022-01-12
AdeptiaSuite6.9.9, 6.9.10, 6.9.11Fixedlinkcisagov2022-01-12
AdobeAutomated Forms Conversion ServiceAffectedlinkcisagov2022-01-12
AdobeColdFusionFixedlinkcisagov2022-01-12
AdobeExperience Manager 6.3 Forms on JEEAll versions from 6.3 GA to 6.3.3Fixedlinkcisagov2022-01-12
AdobeExperience Manager 6.4 Forms DesignerAffectedlinkcisagov2022-01-12
AdobeExperience Manager 6.4 Forms on JEEAll versions from 6.4 GA to 6.4.8Fixedlinkcisagov2022-01-12
AdobeExperience Manager 6.5 Forms DesignerFixedlinkcisagov2022-01-12
AdobeExperience Manager 6.5 Forms on JEEAll versions from 6.5 GA to 6.5.11Fixedlinkcisagov2022-01-12
AdobeExperience Manager Forms on OSGiNot Affectedlinkcisagov2022-01-12
AdobeExperience Manager Forms WorkbenchNot Affectedlinkcisagov2022-01-12
ADPAllUnknownlinkcisagov2022-01-12
Advanced Micro Devices (AMD)AllNot Affectedlinkcisagov2022-02-02
Advanced Systems Concepts (formally Jscape)Active MFTNot AffectedlinkThis advisory is available to customers only and has not been reviewed by CISAcisagov2021-12-14
Advanced Systems Concepts (formally Jscape)MFTNot AffectedlinkThis advisory is available to customers only and has not been reviewed by CISAcisagov2021-12-14
Advanced Systems Concepts (formally Jscape)MFT GatewayNot AffectedlinkThis advisory is available to customers only and has not been reviewed by CISAcisagov2021-12-14
Advanced Systems Concepts (formally Jscape)MFT ServerNot AffectedlinkThis advisory is available to customers only and has not been reviewed by CISAcisagov2021-12-14
AFHCAN Global LLCAFHCANcartNot Affectedlinkcisagov2022-01-12
AFHCAN Global LLCAFHCANmobileNot Affectedlinkcisagov2022-01-12
AFHCAN Global LLCAFHCANServerNot Affectedlinkcisagov2022-01-12
AFHCAN Global LLCAFHCANsuiteNot Affectedlinkcisagov2022-01-12
AFHCAN Global LLCAFHCANupdateNot Affectedlinkcisagov2022-01-12
AFHCAN Global LLCAFHCANwebNot Affectedlinkcisagov2022-01-12
AgilysysAllUnknownlinkcisagov2022-01-12
AhsayMobileNot Affectedlinkcisagov2022-01-12
AhsayOther productsNot Affectedlinkcisagov2022-01-12
AhsayPRDNot Affectedlinkcisagov2022-01-12
AILAllNot Affectedlinkcisagov2022-01-12
AkamaiEnterprise Application Access (EAA) ConnectorNot Affectedlinkcisagov2021-12-15
AkamaiSIEM Integration Connector<1.7.4FixedlinkAkamai SIEM Integration Connector is vulnerable to CVE-2021-44228, CVE-2021-45046 and CVE-2021-45105.cisagov2021-12-15
AkamaiSIEM Splunk Connector< 1.4.10FixedlinkAkamai SIEM Integration Connector for Splunk is not vulnerable to CVE-2021-44228. Although it includes the vulnerable Log4J component, it is not used by the connector.cisagov2021-12-15
AlcatelAllUnknownlinkcisagov2022-01-12
AlertusConsole5.15.0Fixedlinkcisagov2022-01-12
AlexionAlexion CRMNot Affectedlinkcisagov2022-01-12
AlfrescoAlfrescoNot Affectedlinkcisagov2022-01-12
AlienVaultAllUnknownlinkcisagov2022-01-12
Alphatron MedicalAmiSconnectNot Affectedlinkcisagov2022-01-12
Alphatron MedicalCusto Diagnostics5.4, 5.6Affectedlinkcisagov2022-01-12
Alphatron MedicalJiveXNot Affectedlinkcisagov2022-01-12
Alphatron MedicalZorgberichtNot Affectedlinkcisagov2022-01-12
AmazonAMSFixedlinkWork in progress, portion of customers may still be vulnerable. Actively monitoring this issue, and are working on addressing it for any AMS services which use Log4j2.cisagov2022-01-12
AmazonAPI GatewayFixedlinkcisagov2021-12-20
AmazonAthenaFixedlinkcisagov2021-12-20
AmazonAthena JDBC DriverNot AffectedlinkAll versions vended to customers were not affected.cisagov2021-12-20
AmazonAWSNot AffectedlinkAmazon Linux 1 had aws apitools which were Java based but these were deprecated in 2015 AWS Forum. AMIs used to inspect and verify (base spin ups) - amzn-ami-hvm-2018.03.0.20200318.1-x86_64-gp2 and amzn2-ami-kernel-5.10-hvm-2.0.20211201.0-x86_64-gp2.cisagov2021-12-15
AmazonAWS AppFlowFixedlinkcisagov2021-12-20
AmazonAWS AppSyncFixedlinkUpdated to mitigate the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2021-12-20
AmazonAWS Certificate ManagerFixedlinkcisagov2021-12-20
AmazonAWS Certificate Manager Private CAFixedlinkcisagov2021-12-20
AmazonAWS CloudHSM< 3.4.1FixedlinkCloudHSM JCE SDK 3.4.1 or higher is not vulnerable.cisagov2022-01-12
AmazonAWS CodeBuildFixedlinkUpdated to mitigate the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2022-01-12
AmazonAWS CodePipelineFixedlinkUpdated to mitigate the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2022-01-12
AmazonAWS ConnectFixedlinkVendors recommend evaluating components of the environment outside of the Amazon Connect service boundary, which may require separate/additional customer mitigation.cisagov2021-12-23
AmazonAWS Directory ServiceFixedlinkcisagov2021-12-23
AmazonAWS DynamoDBFixedlinkcisagov2021-12-17
AmazonAWS ECSFixedlinkTo help mitigate the impact of the open-source Apache Log4j2 utility (CVE-2021-44228 and CVE-2021-45046) security issues on customers’ containers, Amazon EKS, Amazon ECS, and AWS Fargate are deploying a Linux-based update (hot-patch). This hot-patch will require customer opt-in to use, and disables JNDI lookups from the Log4J2 library in customers’ containers. These updates are available as an Amazon Linux package for Amazon ECS customers, as a DaemonSet for Kubernetes users on AWS, and will be in supported AWS Fargate platform versions.cisagov2021-12-16
AmazonAWS EKSFixedlinkTo help mitigate the impact of the open-source Apache Log4j2 utility (CVE-2021-44228 and CVE-2021-45046) security issues on customers’ containers, Amazon EKS, Amazon ECS, and AWS Fargate are deploying a Linux-based update (hot-patch). This hot-patch will require customer opt-in to use, and disables JNDI lookups from the Log4J2 library in customers’ containers. These updates are available as an Amazon Linux package for Amazon ECS customers, as a DaemonSet for Kubernetes users on AWS, and will be in supported AWS Fargate platform versions.cisagov2021-12-16
AmazonAWS Elastic BeanstalkNot AffectedlinkDefault configuration of applications usage of Log4j versions is not vulnerable.cisagov2021-12-17
AmazonAWS ElastiCacheFixedlinkcisagov2021-12-17
AmazonAWS ELBFixedlinkcisagov2021-12-16
AmazonAWS FargateFixedlinkOpt-in hot-patch to mitigate the Log4j issue in JVM layer will be available as platform versions.cisagov2021-12-16
AmazonAWS GlueFixedlinkHas been updated. Vulnerable only if ETL jobs load affected versions of Apache Log4j.cisagov2021-12-16
AmazonAWS GreengrassFixedlinkUpdates for all Greengrass V2 components Stream Manager (2.0.14) and Secure Tunneling (1.0.6) are available. For Greengrass versions 1.10.x and 1.11.x, an update for the Stream Manager feature is included in Greengrass patch versions 1.10.5 and 1.11.5.cisagov2021-12-16
AmazonAWS InspectorFixedlinkcisagov2021-12-17
AmazonAWS IoT SiteWise EdgeFixedlinkUpdates for all AWS IoT SiteWise Edge components that use Log4j were made available; OPC-UA collector (v2.0.3), Data processing pack (v2.0.14), and Publisher (v2.0.2).cisagov2021-12-17
AmazonAWS Kinesis Data StreamsFixedlinkWe are actively patching all sub-systems that use Log4j2 by applying updates. The Kinesis Client Library (KCL) version 2.X and the Kinesis Producer Library (KPL) are not impacted. For customers using KCL 1.x, we have released an updated version and we strongly recommend that all KCL version 1.x customers upgrade to KCL version 1.14.5 (or higher). KCL 2.x, KCL 1.14.5 or higher, and KPL are not vulnerable.cisagov2021-12-14
AmazonAWS KMSFixedlinkcisagov2022-01-12
AmazonAWS LambdaFixedlinkVulnerable when using aws-lambda-java-log4j2.cisagov2022-01-12
AmazonAWS PollyFixedlinkcisagov2022-01-12
AmazonAWS QuickSightFixedlinkcisagov2022-01-12
AmazonAWS RDSFixedlinkAmazon RDS and Amazon Aurora have been updated to mitigate the issues identified in CVE-2021-44228.cisagov2021-12-17
AmazonAWS S3Fixedlinkcisagov2021-12-14
AmazonAWS SDKNot Affectedlinkcisagov2021-12-14
AmazonAWS Secrets ManagerFixedlinkcisagov2021-12-14
AmazonAWS Service CatalogFixedlinkcisagov2021-12-20
AmazonAWS SNSFixedlinkAmazon SNS systems that serve customer traffic are patched against the Log4j2 issue. We are working to apply the Log4j2 patch to sub-systems that operate separately from SNS’s systems that serve customer traffic.cisagov2021-12-14
AmazonAWS SQSFixedlinkcisagov2021-12-15
AmazonAWS Systems ManagerFixedlinkcisagov2021-12-15
AmazonAWS Systems Manager AgentNot Affectedlinkcisagov2021-12-15
AmazonAWS TextractFixedlinkcisagov2021-12-15
AmazonChimeFixedlinkAmazon Chime and Chime SDK services have been updated to mitigate the issues identified in CVE-2021-44228 and CVE-2021-45046.cisagov2022-01-12
AmazonCloud DirectoryFixedlinkcisagov2022-01-12
AmazonCloudFrontFixedlinkcisagov2022-01-12
AmazonCloudWatchFixedlinkcisagov2022-01-12
AmazonCognitoFixedlinkcisagov2022-01-12
AmazonCorrettoNot Affectedlink10/19 release distribution does not include Log4j. Vulnerable only if customers applications use affected versions of Apache Log4j.cisagov2022-01-12
AmazonDocumentDBFixedlinkcisagov2022-01-12
AmazonEC2FixedlinkPackages for Amazon Linux 1 and 2 not affected, package for Amazon Linux 2022 is affected.cisagov2021-12-15
AmazonECR PublicFixedlinkAmazon-owned images published under a Verified Account on Amazon ECR Public are not affected by the Log4j issue.cisagov2021-12-15
AmazonElastic Load BalancingFixedlinkServices have been updated. All Elastic Load Balancers, as well as Classic, Application, Network and Gateway, are not affected by this Log4j issue.cisagov2021-12-15
AmazonEMRFixedlinkMany customers are estimated to be vulnerable. Vulnerable only if affected EMR releases are used and untrusted sources are configured to be processed.cisagov2022-01-12
AmazonEventBridgeFixedlinkcisagov2022-01-12
AmazonFraud DetectorFixedlinkcisagov2022-01-12
AmazonInspectorFixedlinkcisagov2022-01-12
AmazonInspector ClassicFixedlinkcisagov2022-01-12
AmazonKafka (MSK)FixedlinkApplying updates as required, portion of customers may still be vulnerable. Some MSK-specific service components use Log4j > 2.0.0 library and are being patched where needed.cisagov2022-01-12
AmazonKendraFixedlinkcisagov2022-01-12
AmazonKeyspaces (for Apache Cassandra)Fixedlinkcisagov2022-01-12
AmazonKinesisFixedlinkcisagov2022-01-12
AmazonKinesis Data AnalyticsFixedlinkcisagov2022-01-12
AmazonLake FormationFixedlinkUpdate in progress, portion of customers may still be vulnerable. AWS Lake Formation service hosts are being updated to the latest version of Log4j.cisagov2022-01-12
AmazonLexFixedlinkcisagov2022-01-12
AmazonLinux (AL1)Not AffectedlinkBy default not vulnerable. Opt-in hot-patch to mitigate the Log4j in JVM layer issue is available.cisagov2022-01-12
AmazonLinux (AL2)FixedlinkBy default not vulnerable, and a new version of Amazon Kinesis Agent which is part of AL2 addresses the Log4j issue. Opt-in hot-patch to mitigate the Log4j issue in JVM layer is available.cisagov2022-01-12
AmazonLookout for EquipmentFixedlinkcisagov2022-01-12
AmazonMacieFixedlinkcisagov2022-01-12
AmazonMacie ClassicFixedlinkcisagov2022-01-12
AmazonManaged Workflows for Apache Airflow (MWAA)Fixedlinkcisagov2022-01-12
AmazonMemoryDB for RedisFixedlinkcisagov2022-01-12
AmazonMonitronFixedlinkcisagov2022-01-12
AmazonMQFixedlinkcisagov2022-01-12
AmazonNeptuneFixedlinkcisagov2022-01-12
AmazonNICEFixedlinkRecommended to update EnginFrame or Log4j library.cisagov2022-01-12
AmazonOpenSearchR20211203-P2FixedlinkUpdate released, customers need to update their clusters to the fixed release.cisagov2022-01-12
AmazonPinpointFixedlinkcisagov2022-01-12
AmazonRDS AuroraFixedlinkcisagov2022-01-12
AmazonRDS for OracleFixedlinkcisagov2022-01-12
AmazonRedshiftFixedlinkcisagov2022-01-12
AmazonRekognitionFixedlinkcisagov2022-01-12
AmazonRoute 53Fixedlinkcisagov2022-01-12
AmazonSageMakerFixedlinkCompleted patching for the Apache Log4j2 issue (CVE-2021-44228). Vulnerable only if customers applications use affected versions of Apache Log4j.cisagov2022-01-12
AmazonSimple Notification Service (SNS)FixedlinkSystems that serve customer traffic are patched against the Log4j2 issue. Working to apply the patch to sub-systems that operate separately from SNSs systems that serve customer traffic.cisagov2022-01-12
AmazonSimple Queue Service (SQS)Fixedlinkcisagov2022-01-12
AmazonSimple Workflow Service (SWF)Fixedlinkcisagov2022-01-12
AmazonSingle Sign-OnFixedlinkcisagov2022-01-12
AmazonStep FunctionsFixedlinkcisagov2022-01-12
AmazonTimestreamFixedlinkcisagov2022-01-12
AmazonTranslateNot AffectedlinkService not identified on AWS Log4j Security Bulletincisagov2022-01-12
AmazonVPCFixedlinkcisagov2022-01-12
AmazonWorkSpaces/AppStream 2.0FixedlinkNot affected with default configurations. WorkDocs Sync client versions 1.2.895.1 and older within Windows WorkSpaces, which contain the Log4j component, are vulnerable; For update instruction, see source for more info.cisagov2022-01-12
AMDAllNot AffectedlinkCurrently, no AMD products have been identified as affected. AMD is continuing its analysis.cisagov2021-12-22
AnacondaAllNot Affectedlinkcisagov2021-12-21
AOMEIAllNot Affectedlinkcisagov2021-12-21
ApacheActiveMQ ArtemisNot AffectedlinkActiveMQ Artemis does not use Log4j for logging. However, Log4j 1.2.17 is included in the Hawtio-based web console application archive (i.e. web/console.war/WEB-INF/lib). Although this version of Log4j is not impacted by CVE-2021-44228 future versions of Artemis will be updated so that the Log4j jar is no longer included in the web console application archive. See ARTEMIS-3612 for more information on that task.cisagov2021-12-21
ApacheAirflowNot AffectedlinkAirflow is written in Pythoncisagov2022-01-12
ApacheArchiva2.2.6FixedlinkFixed in 2.2.6.cisagov2022-01-12
ApacheCamelNot AffectedlinkApache Camel does not directly depend on Log4j 2, so we are not affected by CVE-2021-44228.If you explicitly added the Log4j 2 dependency to your own applications, make sure to upgrade.Apache Camel does use log4j during testing itself, and therefore you can find that we have been using log4j v2.13.3 release in our latest LTS releases Camel 3.7.6, 3.11.4.cisagov2021-12-13
ApacheCamel 2Not Affectedlinkcisagov2021-12-13
ApacheCamel JBang<=3.1.4Affectedlinkcisagov2021-12-13
ApacheCamel KNot Affectedlinkcisagov2021-12-13
ApacheCamel Kafka ConnectorNot Affectedlinkcisagov2021-12-13
ApacheCamel KarafAffectedlinkThe Karaf team is aware of this and are working on a new Karaf 4.3.4 release with updated log4j.cisagov2021-12-13
ApacheCamel QuarkusNot Affectedlinkcisagov2021-12-13
ApacheCassandraNot Affectedlinkcisagov2021-12-13
ApacheDruid0.22.1Fixedlinkcisagov2021-12-12
ApacheDubboAllFixedlinkcisagov2021-12-12
ApacheFlink1.15.0, 1.14.2, 1.13.5, 1.12.7, 1.11.6FixedlinkTo clarify and avoid confusion, the 1.14.1 / 1.13.4 / 1.12.6 / 1.11.5 releases, which were supposed to only contain a Log4j upgrade to 2.15.0, were skipped because CVE-2021-45046 was discovered during the release publication. The new 1.14.2 / 1.13.5 / 1.12.7 / 1.11.6 releases include a version upgrade for Log4j to version 2.16.0 to address CVE-2021-44228 and CVE-2021-45046.https://flink.apache.org/news/2021/12/16/log4j-patch-releases.htmlcisagov2021-12-12
ApacheFortress< 2.0.7FixedlinkFixed in 2.0.7.cisagov2021-12-14
ApacheGeode1.14.0FixedlinkFixed in 1.12.6, 1.13.5, 1.14.1.cisagov2021-12-14
ApacheGuacamoleNot Affectedlinkcisagov2021-12-14
ApacheHadoopNot Affectedlinkcisagov2021-12-14
ApacheHBaseAffectedlinkcisagov2021-12-14
ApacheHive4.xFixedlinkcisagov2021-12-14
ApacheJames3.6.0Affectedlinkcisagov2021-12-14
ApacheJena< 4.3.1Fixedlinkcisagov2021-12-14
ApacheJMeterAllAffectedlinkcisagov2021-12-14
ApacheJSPWiki2.11.1Fixedlinkcisagov2021-12-14
ApacheKafkaNot AffectedlinkUses Log4j 1.2.17.cisagov2021-12-14
ApacheLog4j 1.xNot Affectedlinkcisagov2022-01-12
ApacheLog4j 2.x2.17.1AffectedlinkFixed in Log4j 2.17.1 (Java 8), 2.12.4 (Java 7) and 2.3.2 (Java 6).cisagov2022-01-12
ApacheMavenNot Affectedlinkcisagov2022-01-12
ApacheNiFiNot AffectedlinkFixed in 1.15.1, 1.16.0.cisagov2022-01-12
ApacheOFBiz< 18.12.03Fixedlinkcisagov2022-01-12
ApacheOzone< 1.2.1FixedlinkFixed in 1.15.1, 1.16.0.cisagov2022-01-12
ApacheSkyWalking< 8.9.1Fixedlinkcisagov2022-01-12
ApacheSOLR7.4.0 to 7.7.3, 8.0.0 to 8.11.0FixedlinkFixed in 8.11.1, Versions before 7.4 also vulnerable when using several configurations.Apache Solr 8.11.1 downloadscisagov2021-12-16
ApacheSparkNot AffectedlinkUses log4j 1.xcisagov2022-01-12
ApacheStruts2.5.28Affectedlinkcisagov2022-01-12
ApacheStruts 2Versions before 2.5.28.1FixedlinkThe Apache Struts group is pleased to announce that Struts 2.5.28.1 is available as a General Availability release. The GA designation is our highest quality grade. This release addresses Log4j vulnerability CVE-2021-45046 by using the latest Log4j 2.12.2 version (Java 1.7 compatible).Apache Struts Release Downloadscisagov2021-12-21
ApacheTapestry5.7.3Affectedlinkcisagov2022-01-12
ApacheTika2.0.0 and upAffectedlinkcisagov2022-01-12
ApacheTomcatUnknownlinkApache Tomcat 9.0.x has no dependency on any version of log4j. Web applications deployed on Apache Tomcat may have a dependency on log4j. You should seek support from the application vendor in this instance. It is possible to configure Apache Tomcat 9.0.x to use log4j 2.x for Tomcats internal logging. This requires explicit configuration and the addition of the log4j 2.x library. Anyone who has switched Tomcats internal logging to log4j 2.x is likely to need to address this vulnerability. In most cases, disabling the problematic feature will be the simplest solution. Exactly how to do that depends on the exact version of log4j 2.x being used. Details are provided on the log4j 2.x security pagecisagov2021-12-21
ApacheTrafficControlAffectedlinkcisagov2022-01-12
ApacheZooKeeperNot Affectedlinkcisagov2022-01-12
APC by Schneider ElectricPowerchute Business Editionv9.5, v10.0.1, v10.0.2, v10.0.3, v10.0.4FixedlinkMitigation instructions to remove the affected class.cisagov2021-12-15
APC by Schneider ElectricPowerchute Network Shutdown4.2, 4.3, 4.4, 4.4.1FixedlinkMitigation instructions to remove the affected class.cisagov2021-12-15
ApereoCAS6.3.x, 6.4.xFixedlinkOther versions still in active maintainance might need manual inspection.cisagov2022-01-12
ApereoOpencast< 9.10, < 10.6Fixedlinkcisagov2022-01-12
ApigeeEdge and OPDK productsNot Affectedlinkcisagov2022-01-12
ApolloAllUnknownlinkcisagov2022-01-12
AppdynamicsAllUnknownlinkcisagov2022-01-12
AppeonPowerBuilderAppeon PowerBuilder 2017-2021 regardless of product editionAffectedlinkcisagov2021-12-15
AppGateAllUnknownlinkcisagov2022-01-12
AppianAppian PlatformAllFixedlinkcisagov2021-12-22
Application Performance LtdDBMarlinUnknownlinkcisagov2021-12-15
APPSHEETAllUnknownlinkcisagov2022-01-12
AptibleAllSearch 5.xFixedlinkcisagov2022-01-12
Aqua SecurityAllUnknownlinkcisagov2022-01-12
Arbiter SystemsAllNot Affectedlinkcisagov2021-12-22
ARC InformatiqueAllNot Affectedlinkcisagov2022-01-13
Arca NoaeAllUnknownlinkcisagov2022-01-12
ArcserveArcserve BackupNot Affectedlinkhttps://support.storagecraft.com/s/question/0D51R000089NnT3SAK/does-storagecraft-have-a-publicly-available-response-to-the-log4j-vulnerability-is-there-a-reference-for-any-findings-negative-positive-the-company-has-in-their-investigations-it-seems-it-would-greatly-benefit-support-and-customers-both?language=en_UScisagov2021-12-14
ArcserveArcserve Continuous AvailabilityNot Affectedlinkhttps://support.storagecraft.com/s/question/0D51R000089NnT3SAK/does-storagecraft-have-a-publicly-available-response-to-the-log4j-vulnerability-is-there-a-reference-for-any-findings-negative-positive-the-company-has-in-their-investigations-it-seems-it-would-greatly-benefit-support-and-customers-both?language=en_UScisagov2021-12-14
ArcserveArcserve Email ArchivingNot Affectedlinkhttps://support.storagecraft.com/s/question/0D51R000089NnT3SAK/does-storagecraft-have-a-publicly-available-response-to-the-log4j-vulnerability-is-there-a-reference-for-any-findings-negative-positive-the-company-has-in-their-investigations-it-seems-it-would-greatly-benefit-support-and-customers-both?language=en_UScisagov2021-12-14
ArcserveArcserve UDPNot Affectedlinkhttps://support.storagecraft.com/s/question/0D51R000089NnT3SAK/does-storagecraft-have-a-publicly-available-response-to-the-log4j-vulnerability-is-there-a-reference-for-any-findings-negative-positive-the-company-has-in-their-investigations-it-seems-it-would-greatly-benefit-support-and-customers-both?language=en_UScisagov2021-12-14
ArcserveShadowProtectNot Affectedlinkhttps://support.storagecraft.com/s/question/0D51R000089NnT3SAK/does-storagecraft-have-a-publicly-available-response-to-the-log4j-vulnerability-is-there-a-reference-for-any-findings-negative-positive-the-company-has-in-their-investigations-it-seems-it-would-greatly-benefit-support-and-customers-both?language=en_UScisagov2021-12-14
ArcserveShadowXafeNot Affectedlinkhttps://support.storagecraft.com/s/question/0D51R000089NnT3SAK/does-storagecraft-have-a-publicly-available-response-to-the-log4j-vulnerability-is-there-a-reference-for-any-findings-negative-positive-the-company-has-in-their-investigations-it-seems-it-would-greatly-benefit-support-and-customers-both?language=en_UScisagov2021-12-14
ArcserveSoloNot Affectedlinkhttps://support.storagecraft.com/s/question/0D51R000089NnT3SAK/does-storagecraft-have-a-publicly-available-response-to-the-log4j-vulnerability-is-there-a-reference-for-any-findings-negative-positive-the-company-has-in-their-investigations-it-seems-it-would-greatly-benefit-support-and-customers-both?language=en_UScisagov2021-12-14
ArcserveStorageCraft OneXafeNot Affectedlinkhttps://support.storagecraft.com/s/question/0D51R000089NnT3SAK/does-storagecraft-have-a-publicly-available-response-to-the-log4j-vulnerability-is-there-a-reference-for-any-findings-negative-positive-the-company-has-in-their-investigations-it-seems-it-would-greatly-benefit-support-and-customers-both?language=en_UScisagov2021-12-14
ArcticWolfAllUnknownlinkcisagov2022-01-12
ArduinoIDE1.8.17Fixedlinkcisagov2022-01-12
AribaAllUnknownlinkcisagov2022-01-12
AristaAnalytics Node for Converged Cloud Fabric>7.0.0AffectedlinkFormerly Big Cloud Fabriccisagov2022-01-12
AristaAnalytics Node for DANZ Monitoring Fabric>7.0.0AffectedlinkFormerly Big Monitoring Fabriccisagov2022-01-12
AristaCloudVision Portal>2019.1.0Affectedlinkcisagov2022-01-12
AristaCloudVision Wi-Fi, virtual or physical appliance>8.8Affectedlinkcisagov2022-01-12
AristaEmbedded Analytics for Converged Cloud Fabric>5.3.0AffectedlinkFormerly Big Cloud Fabriccisagov2022-01-12
Aruba NetworksAirWave Management PlatformNot Affectedlinkcisagov2022-01-12
Aruba NetworksAnalytics and Location EngineNot Affectedlinkcisagov2022-01-12
Aruba NetworksArubaOS SD-WAN GatewaysNot Affectedlinkcisagov2022-01-12
Aruba NetworksArubaOS Wi-Fi Controllers and GatewaysNot Affectedlinkcisagov2022-01-12
Aruba NetworksArubaOS-CX SwitchesNot Affectedlinkcisagov2022-01-12
Aruba NetworksArubaOS-S SwitchesNot Affectedlinkcisagov2022-01-12
Aruba NetworksCentralNot Affectedlinkcisagov2022-01-12
Aruba NetworksCentral On-PremNot Affectedlinkcisagov2022-01-12
Aruba NetworksClearPass Policy ManagerNot Affectedlinkcisagov2022-01-12
Aruba NetworksEdgeConnectNot Affectedlinkcisagov2022-01-12
Aruba NetworksFabric Composer (AFC)Not Affectedlinkcisagov2022-01-12
Aruba NetworksHP ProCurve SwitchesNot Affectedlinkcisagov2022-01-12
Aruba NetworksInstantNot Affectedlinkcisagov2022-01-12
Aruba NetworksInstant Access PointsNot Affectedlinkcisagov2022-01-12
Aruba NetworksInstant OnNot Affectedlinkcisagov2022-01-12
Aruba NetworksIntroSpectVersions 2.5.0.0 to 2.5.0.6Fixedlinkcisagov2022-01-12
Aruba NetworksLegacy GMS ProductsFixedlinkcisagov2022-01-12
Aruba NetworksLegacy NXNot Affectedlinkcisagov2022-01-12
Aruba NetworksLegacy VRXNot Affectedlinkcisagov2022-01-12
Aruba NetworksLegacy VXNot Affectedlinkcisagov2022-01-12
Aruba NetworksNetEditNot Affectedlinkcisagov2022-01-12
Aruba NetworksPlexxi Composable Fabric Manager (CFM)Not Affectedlinkcisagov2022-01-12
Aruba NetworksSilver Peak OrchestratorFixedlinkcisagov2022-01-12
Aruba NetworksUser Experience Insight (UXI)Not Affectedlinkcisagov2022-01-12
Aruba NetworksVIA ClientsNot Affectedlinkcisagov2022-01-12
AtaccamaAllUnknownlinkcisagov2022-01-12
AteraAllUnknownlinkcisagov2022-01-12
AtlassianBamboo Server & Data CenterOn PremAffectedlinkOnly vulnerable when using non-default config, cloud version fixed.cisagov2022-01-12
AtlassianBitbucket Server & Data CenterOn premFixedlinkThis product is not vulnerable to remote code execution but may leak information due to the bundled Elasticsearch component being vulnerable.cisagov2022-01-12
AtlassianConfluence Server & Data CenterOn premAffectedlinkOnly vulnerable when using non-default config, cloud version fixed.cisagov2022-01-12
AtlassianConfluence-CIS CSAT Prov1.7.1Affectedlinkcisagov2022-01-12
AtlassianConfluence-CIS WorkBenchNot Affectedlinkcisagov2022-01-12
AtlassianConfluence-CIS-CAT Litev4.13.0Affectedlinkcisagov2022-01-12
AtlassianConfluence-CIS-CAT Pro Assessor v3 Full and Dissolvablev3.0.77Affectedlinkcisagov2022-01-12
AtlassianConfluence-CIS-CAT Pro Assessor v4v4.13.0Affectedlinkcisagov2022-01-12
AtlassianConfluence-CIS-CAT Pro Assessor v4 Servicev1.13.0Affectedlinkcisagov2022-01-12
AtlassianConfluence-CIS-CAT Pro DashboardNot Affectedlinkcisagov2022-01-12
AtlassianConfluence-CIS-Hosted CSATNot Affectedlinkcisagov2022-01-12
AtlassianCrowd Server & Data CenterOn premAffectedlinkThis product may be affected by a related but lower severity vulnerability if running in a specific non-default configuration.cisagov2022-01-12
AtlassianCrucibleOn premAffectedlinkThis product may be affected by a related but lower severity vulnerability if running in a specific non-default configuration.cisagov2022-01-12
AtlassianFisheyeOn premAffectedlinkThis product may be affected by a related but lower severity vulnerability if running in a specific non-default configuration.cisagov2022-01-12
AtlassianJira Server & Data CenterOn premAffectedlinkThis product may be affected by a related but lower severity vulnerability if running in a specific non-default configuration.cisagov2022-01-12
Attivo NetworksAllUnknownlinkcisagov2022-01-12
AtviseAllNot AffectedlinkThe security vulnerability does NOT affect our applications and products or pose any threat. This applies to all Bachmann applications and products, including atvise solutions.cisagov2022-01-17
AudioCodesAllUnknownlinkcisagov2022-01-12
AutodeskAllUnknownlinkAutodesk is continuing to perform a thorough investigation in relation to the recently discovered Apache Log4j security vulnerabilities. We continue to implement several mitigating factors for our products including patching, network firewall blocks, and updated detection signatures to reduce the threat of this vulnerability and enhance our ability to quickly respond to potential malicious activity. We have not identified any compromised systems in the Autodesk environment due to this vulnerability, at this time. This is an ongoing investigation and we will provide updates on the Autodesk Trust Center as we learn more.cisagov2021-12-21
Automation AnywhereAutomation 360 CloudFixedlinkThis advisory is available to customer only and has not been reviewed by CISA.cisagov2022-01-12
Automation AnywhereAutomation 360 On PremiseFixedlinkThis advisory is available to customer only and has not been reviewed by CISA.cisagov2022-01-12
Automation AnywhereAutomation Anywhere11.x, <11.3xFixedlinkThis advisory is available to customer only and has not been reviewed by CISA.cisagov2022-01-12
AutomoxAllUnknownlinkcisagov2022-01-12
AutopsyAllUnknownlinkcisagov2022-01-12
AuvikAllUnknownlinkcisagov2022-01-12
Avantra SYSLINKAllUnknownlinkcisagov2022-01-12
AvayaAvaya Analytics3.5, 3.6, 3.6.1, 3.7, 4Affectedlinkcisagov2021-12-14
AvayaAvaya Aura Application Enablement Services8.1.3.2, 8.1.3.3, 10.1AffectedlinkPSN020551ucisagov2021-12-14
AvayaAvaya Aura Contact Center7.0.2, 7.0.3, 7.1, 7.1.1, 7.1.2Affectedlinkcisagov2021-12-14
AvayaAvaya Aura Device Services8, 8.0.1, 8.0.2, 8.1, 8.1.3, 8.1.4, 8.1.5Affectedlinkcisagov2021-12-14
AvayaAvaya Aura for OneCloud PrivateAffectedlinkAvaya is scanning and monitoring its OneCloud Private environments as part of its management activities. Avaya will continue to monitor this fluid situation and remediations will be made as patches become available, in accordance with appropriate change processes.cisagov2021-12-14
AvayaAvaya Aura Media Server8.0.0, 8.0.1, 8.0.2AffectedlinkPSN020549ucisagov2021-12-14
AvayaAvaya Aura Presence Services10.1, 7.1.2, 8, 8.0.1, 8.0.2, 8.1, 8.1.1, 8.1.2, 8.1.3, 8.1.4Affectedlinkcisagov2021-12-14
AvayaAvaya Aura Session Manager10.1, 7.1.3, 8, 8.0.1, 8.1, 8.1.1, 8.1.2, 8.1.3AffectedlinkPSN020550ucisagov2021-12-14
AvayaAvaya Aura System Manager10.1, 8.1.3AffectedlinkPSN005565ucisagov2021-12-14
AvayaAvaya Aura Web Gateway3.11[P], 3.8.1[P], 3.8[P], 3.9.1[P], 3.9[P]Affectedlinkcisagov2021-12-14
AvayaAvaya Breeze3.7, 3.8, 3.8.1Affectedlinkcisagov2021-12-14
AvayaAvaya Contact Center Select7.0.2, 7.0.3, 7.1, 7.1.1, 7.1.2Affectedlinkcisagov2021-12-14
AvayaAvaya CRM Connector - Connected Desktop2.2Affectedlinkcisagov2021-12-14
AvayaAvaya Device Enablement Service3.1.22Affectedlinkcisagov2021-12-14
AvayaAvaya Meetings9.1.10, 9.1.11, 9.1.12Affectedlinkcisagov2021-12-14
AvayaAvaya OneCloud-Private2Affectedlinkcisagov2021-12-14
AvayaAvaya OneCloud-Private-UCaaS - Mid Market Aura1Affectedlinkcisagov2021-12-14
AvayaAvaya Session Border Controller for Enterprise8.0.1, 8.1, 8.1.1, 8.1.2, 8.1.3AffectedlinkPSN020554ucisagov2021-12-14
AvayaAvaya Social Media HubAffectedlinkcisagov2021-12-14
AvayaAvaya Workforce Engagement5.3Affectedlinkcisagov2021-12-14
AvayaBusiness Rules Engine3.4, 3.5, 3.6, 3.7Affectedlinkcisagov2021-12-14
AvayaCallback Assist5, 5.0.1Affectedlinkcisagov2021-12-14
AvayaControl Manager9.0.2, 9.0.2.1Affectedlinkcisagov2021-12-14
AvayaDevice Enrollment Service3.1Affectedlinkcisagov2021-12-14
AvayaEquinox Conferencing9.1.2Affectedlinkcisagov2021-12-14
AvayaInteraction Center7.3.9Affectedlinkcisagov2021-12-14
AvayaIP Office Platform11.0.4, 11.1, 11.1.1, 11.1.2Affectedlinkcisagov2021-12-14
AvayaProactive Outreach Manager3.1.2, 3.1.3, 4, 4.0.1Affectedlinkcisagov2021-12-14
AVEPOINTAllUnknownlinkcisagov2022-01-12
AVMAllNot Affectedlinkdevices, firmware, software incl. MyFritz Service.cisagov2022-01-12
AvTech RoomAlertAllUnknownlinkcisagov2022-01-12
AXISOSNot Affectedlinkcisagov2022-01-12
AXONAllUnknownlinkcisagov2022-01-12
AXS GuardAllUnknownlinkcisagov2022-01-12
Axways ApplicationsAllUnknownlinkcisagov2022-01-12