CISA Log4j (CVE-2021-44228) Affected Vendor & Software List

March 1, 2022 ยท View on GitHub

0-9 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Status Descriptions

StatusDescription
UnknownStatus unknown. Default choice.
AffectedReported to be affected by CVE-2021-44228.
Not AffectedReported to NOT be affected by CVE-2021-44228 and no further action necessary.
FixedPatch and/or mitigations available (see provided links).
Under InvestigationVendor investigating status.

Software List

This list has been populated using information from the following sources:

  • Kevin Beaumont
  • SwitHak
  • National Cyber Security Centre - Netherlands (NCSC-NL)

NOTE: This file is automatically generated. To submit updates, please refer to CONTRIBUTING.md.

VendorProductAffected VersionsPatched VersionsStatusVendor LinksNotesReferencesReporterLast Updated
Objectif LuneUnknownlinkcisagov2022-01-12
OCLCUnknownlinkcisagov2022-01-12
OctopusUnknownlinkcisagov2022-01-12
OktaAdvanced Server AccessUnknownlinkcisagov2021-12-12
OktaOkta Access GatewayUnknownlinkcisagov2021-12-12
OktaOkta AD AgentUnknownlinkcisagov2021-12-12
OktaOkta Browser PluginUnknownlinkcisagov2021-12-12
OktaOkta IWA Web AgentUnknownlinkcisagov2021-12-12
OktaOkta LDAP AgentUnknownlinkcisagov2021-12-12
OktaOkta MobileUnknownlinkcisagov2021-12-12
OktaOkta On-Prem MFA Agent< 1.4.6Affectedlinkcisagov2021-12-12
OktaOkta RADIUS Server Agent< 2.17.0Affectedlinkcisagov2021-12-12
OktaOkta VerifyUnknownlinkcisagov2021-12-12
OktaOkta WorkflowsUnknownlinkcisagov2021-12-12
OnespanUnknownlinkcisagov2022-01-12
OpengearUnknownlinkcisagov2022-01-12
OpenMRS TALKUnknownlinkcisagov2022-01-12
OpenNMSUnknownlinkcisagov2022-01-12
OpenSearchUnknownlinkcisagov2022-01-12
OpenTextUnknownlinkcisagov2021-12-23
Opto 22GROOV-AR1, GROOV-AR1-BASE, GROOV-AR1-SNAP< 4.3g4.3gFixedlinkThe Log4j vulnerability affects all products running groov View softwarecisagov2022-01-13
Opto 22GROOV-AT1, GROOV-AT1-SNAP< 4.3g4.3gFixedlinkThe Log4j vulnerability affects all products running groov View softwarecisagov2022-01-13
Opto 22GROOV-SVR-WIN, GROOV-SVR-WIN-BASE, GROOV-SVR-WIN-SNAP< 4.3g4.3gFixedlinkThe Log4j vulnerability affects all products running groov View softwarecisagov2022-01-13
Opto 22GRV-EPIC-PR1, GRV-EPIC-PR2< 3.3.23.3.2FixedlinkThe Log4j vulnerability affects all products running groov View softwarecisagov2022-01-13
OracleUnknownlinkThe support document is available to customers only and has not been reviewed by CISAcisagov2021-12-17
OracleEnterprise Manager13.5, 13.4 & 13.3.2AffectedlinkPatch status and other security guidance is restricted to Oracle account/support members. The support document is available to customers only and has not been reviewed by CISA.cisagov2021-12-17
OracleExadata<21.3.4AffectedlinkPatch status and other security guidance is restricted to Oracle account/support members. The support document is available to customers only and has not been reviewed by CISA.cisagov2021-12-17
OrgavisionUnknownlinkcisagov2022-01-12
OsiriumPAMUnknownlinkcisagov2022-01-12
OsiriumPEMUnknownlinkcisagov2022-01-12
OsiriumPPAUnknownlinkcisagov2022-01-12
OTRSUnknownlinkcisagov2022-01-12
OVHCloudUnknownlinkcisagov2022-01-12
OwnCloudUnknownlinkcisagov2022-01-12
OxygenXMLAuthorUnknownhttps://www.oxygenxml.com/security/advisory/CVE-2021-44228.htmlcisagov2021-12-17
OxygenXMLDeveloperUnknownhttps://www.oxygenxml.com/security/advisory/CVE-2021-44228.htmlcisagov2021-12-17
OxygenXMLEditorUnknownhttps://www.oxygenxml.com/security/advisory/CVE-2021-44228.htmlcisagov2021-12-17
OxygenXMLOxygen Content Fusion2.0, 3.0, 4.1Affectedhttps://www.oxygenxml.com/security/advisory/CVE-2021-44228.htmlcisagov2021-12-17
OxygenXMLOxygen Feedback Enterprise1.4.4 & olderAffectedhttps://www.oxygenxml.com/security/advisory/CVE-2021-44228.htmlcisagov2021-12-17
OxygenXMLOxygen License Serverv22.1 to v24.0Affectedhttps://www.oxygenxml.com/security/advisory/CVE-2021-44228.htmlcisagov2021-12-17
OxygenXMLOxygen PDF Chemistryv22.1, 23.0, 23.1, 24.0Affectedhttps://www.oxygenxml.com/security/advisory/CVE-2021-44228.htmlcisagov2021-12-17
OxygenXMLOxygen SDKUnknownhttps://www.oxygenxml.com/security/advisory/CVE-2021-44228.htmlcisagov2021-12-17
OxygenXMLPlugins (see advisory link)Unknownhttps://www.oxygenxml.com/security/advisory/CVE-2021-44228.htmlcisagov2021-12-17
OxygenXMLPublishing EngineUnknownhttps://www.oxygenxml.com/security/advisory/CVE-2021-44228.htmlcisagov2021-12-17
OxygenXMLWeb AuthorUnknownhttps://www.oxygenxml.com/security/advisory/CVE-2021-44228.htmlcisagov2021-12-17
OxygenXMLWebHelpUnknownhttps://www.oxygenxml.com/security/advisory/CVE-2021-44228.htmlcisagov2021-12-17