CISA Log4j (CVE-2021-44228) Affected Vendor & Software List

March 1, 2022 · View on GitHub

0-9 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Status Descriptions

StatusDescription
UnknownStatus unknown. Default choice.
AffectedReported to be affected by CVE-2021-44228.
Not AffectedReported to NOT be affected by CVE-2021-44228 and no further action necessary.
FixedPatch and/or mitigations available (see provided links).
Under InvestigationVendor investigating status.

Software List

This list has been populated using information from the following sources:

  • Kevin Beaumont
  • SwitHak
  • National Cyber Security Centre - Netherlands (NCSC-NL)

NOTE: This file is automatically generated. To submit updates, please refer to CONTRIBUTING.md.

VendorProductAffected VersionsPatched VersionsStatusVendor LinksNotesReferencesReporterLast Updated
SAE-ITUnknownlinkcisagov2022-01-12
SAFE FME ServerUnknownlinkcisagov2022-01-12
SAGEUnknownlinkcisagov2022-01-12
SailPointUnknownlinkThis advisory is available to customers only and has not been reviewed by CISAcisagov2022-01-12
SalesforceAnalytics CloudAllFixedlinkAnalytics Cloud was affected by CVE-2021-44228 and CVE-2021-45046. Salesforce-owned services and third-party vendors have been patched to address the issues currently identified in CVE-2021-44228 and CVE-2021-45046.cisagov2022-01-26
SalesforceB2C Commerce CloudAllFixedlinkB2C Commerce Cloud was affected by CVE-2021-44228 and CVE-2021-45046. Salesforce-owned services and third-party vendors have been patched to address the issues currently identified in CVE-2021-44228 and CVE-2021-45046.cisagov2022-01-26
SalesforceClickSoftware (As-a-Service)AllFixedlinkClickSoftware (As-a-Service) was affected by CVE-2021-44228 and CVE-2021-45046. Salesforce-owned services and third-party vendors have been patched to address the issues currently identified in CVE-2021-44228 and CVE-2021-45046.cisagov2022-01-26
SalesforceClickSoftware (On-Premise)AllFixedlinkClickSoftware (On-Premise) was affected by CVE-2021-44228 and CVE-2021-45046. Salesforce-owned services and third-party vendors have been patched to address the issues currently identified in CVE-2021-44228 and CVE-2021-45046. Additional details are available here.cisagov2022-01-26
SalesforceData.comAllFixedlinkData.com was affected by CVE-2021-44228 and CVE-2021-45046. Salesforce-owned services and third-party vendors have been patched to address the issues currently identified in CVE-2021-44228 and CVE-2021-45046.cisagov2022-01-26
SalesforceDataLoader>=53.0.2FixedlinkThis version is for use with Salesforce Winter '22 or higher release through Salesforce Force Partner API and Force WSC v53.0.0. It contains the fix for CVE-2021-44228, CVE-2021-45046, and CVE-2021-45105 by upgrading to log4j 2.17.0.cisagov2022-01-26
SalesforceDatoramaAllFixedlinkDatorama was affected by CVE-2021-44228 and CVE-2021-45046. Salesforce-owned services and third-party vendors have been patched to address the issues currently identified in CVE-2021-44228 and CVE-2021-45046.cisagov2022-01-26
SalesforceEvergage (Interaction Studio)AllFixedlinkEvergage (Interaction Studio) was affected by CVE-2021-44228 and CVE-2021-45046. Salesforce-owned services and third-party vendors have been patched to address the issues currently identified in CVE-2021-44228 and CVE-2021-45046.cisagov2022-01-26
SalesforceExperience (Community) CloudAllFixedlinkExperience Cloud was affected by CVE-2021-44228 and CVE-2021-45046. Salesforce-owned services and third-party vendors have been patched to address the issues currently identified in CVE-2021-44228 and CVE-2021-45046.cisagov2022-01-26
SalesforceForce.comAllFixedlinkForce.com was affected by CVE-2021-44228 and CVE-2021-45046. Salesforce-owned services and third-party vendors have been patched to address the issues currently identified in CVE-2021-44228 and CVE-2021-45046. The Data Loader tool has been patched to address the issues currently identified in CVE-2021-44228 and CVE-2021-45046. Make sure that you are using Data Loader version 53.0.2 or later. Follow the steps described here to download the latest version of Data Loader.cisagov2022-01-26
SalesforceHerokuNot AffectedlinkHeroku is reported to not be affected by the issues currently identified in CVE-2021-44228 or CVE-2021-45046.cisagov2022-01-26
SalesforceMarketing CloudAllFixedlinkSalesforce-owned services within Marketing Cloud are not affected by the issues currently identified in CVE-2021-44228 or CVE-2021-45046. Third-party vendors have been patched to address the security issues currently identified in CVE-2021-44228 or CVE-2021-45046.cisagov2022-01-26
SalesforceMuleSoft (Cloud)AllFixedlinkMuleSoft (Cloud) was affected by CVE-2021-44228 and CVE-2021-45046. Mulesoft services, including dataloader.io, have been updated to mitigate the issues currently identified in CVE-2021-44228 and CVE-2021-45046. Please see additional details here.cisagov2022-01-26
SalesforceMuleSoft (On-Premise)AllFixedlinkMuleSoft (On-Premise) was affected by CVE-2021-44228 and CVE-2021-45046. Salesforce-owned services and third-party vendors, including Private Cloud Edition (PCE) and Anypoint Studio, have a mitigation in place to address the issues currently identified in CVE-2021-44228 and CVE-2021-45046. Please see additional details here.cisagov2022-01-26
SalesforcePardotAllFixedlinkPardot was affected by CVE-2021-44228 and CVE-2021-45046. Salesforce-owned services and third-party vendors have been patched to address the issues currently identified in CVE-2021-44228 and CVE-2021-45046.cisagov2022-01-26
SalesforceSales CloudAllFixedlinkSales Cloud was affected by CVE-2021-44228 and CVE-2021-45046. Salesforce-owned services and third-party vendors have been patched to address the issues currently identified in CVE-2021-44228 and CVE-2021-45046.cisagov2022-01-26
SalesforceService CloudAllFixedlinkService Cloud was affected by CVE-2021-44228 and CVE-2021-45046. Salesforce-owned services and third-party vendors have been patched to address the issues currently identified in CVE-2021-44228 and CVE-2021-45046.cisagov2022-01-26
SalesforceSlackAllFixedlinkSlack was affected by CVE-2021-44228 and CVE-2021-45046. Salesforce-owned services and third-party vendors have been patched to address the issues currently identified in both CVE-2021-44228 and CVE-2021-45046. Additional details are available here.cisagov2022-01-26
SalesforceSocial StudioAllFixedlinkSocial Studio was affected by CVE-2021-44228 and CVE-2021-45046. Salesforce-owned services and third-party vendors have been patched to address the issues currently identified in CVE-2021-44228 and CVE-2021-45046.cisagov2022-01-26
SalesforceTableau (On-Premise)< 2021.4.1FixedlinkTableau (On-Premise) was affected by CVE-2021-44228 and CVE-2021-45046. Patches to address the issues currently identified in both CVE-2021-44228 and CVE-2021-45046 are available for download. Additional details are available here.cisagov2021-12-16
SalesforceTableau (Online)AllFixedlinkTableau Online was affected by CVE-2021-44228 and CVE-2021-45046. Services have been patched to mitigate the issues currently identified in both CVE-2021-44228 and CVE-2021-45046.cisagov2022-01-26
Samsung Electronics AmericaKnox Admin PortalNot Affectedlinkcisagov2022-01-17
Samsung Electronics AmericaKnox Asset IntelligenceNot Affectedlinkcisagov2022-01-17
Samsung Electronics AmericaKnox ConfigureNot Affectedlinkcisagov2022-01-17
Samsung Electronics AmericaKnox E-FOTA OneNot Affectedlinkcisagov2022-01-17
Samsung Electronics AmericaKnox GuardNot Affectedlinkcisagov2022-01-17
Samsung Electronics AmericaKnox License ManagementNot Affectedlinkcisagov2022-01-17
Samsung Electronics AmericaKnox ManageCloudFixedlinkcisagov2022-01-17
Samsung Electronics AmericaKnox Managed Services Provider (MSP)Not Affectedlinkcisagov2022-01-17
Samsung Electronics AmericaKnox Mobile EnrollmentNot Affectedlinkcisagov2022-01-17
Samsung Electronics AmericaKnox Reseller PortalCloudFixedlinkcisagov2022-01-17
SangomaUnknownlinkcisagov2022-01-12
SAPUnknownlinkThis advisory is available to customers only and has not been reviewed by CISAcisagov2021-12-17
SAP Advanced PlatformUnknownlinkThis advisory is available to customers only and has not been reviewed by CISAcisagov2021-12-17
SAP BusinessObjectsUnknownlinkThe support document is available to customers only and has not been reviewed by CISAcisagov2021-12-17
SASUnknownlinkcisagov2022-01-12
SASSAFRASUnknownlinkcisagov2022-01-12
Savignano software solutionsUnknownlinkcisagov2022-01-12
SBTSBT<1.5.6Affectedlinkcisagov2021-12-15
ScaleComputingUnknownlinkThis advisory is available to customers only and has not been reviewed by CISAcisagov2022-01-12
ScaleFusion MobileLock ProUnknownlinkcisagov2022-01-12
Schneider ElectricEASYFITCurrent software and earlierAffectedlinkcisagov2021-12-20
Schneider ElectricEcoreal XLCurrent software and earlierAffectedlinkcisagov2021-12-20
Schneider ElectricEcoStruxure IT ExpertCloudFixedcisagov2021-12-20
Schneider ElectricEcoStruxure IT GatewayV1.5.0 to V1.13.0Fixedlinkcisagov2021-12-20
Schneider ElectricEurotherm Data ReviewerV3.0.2 and priorAffectedlinkcisagov2021-12-20
Schneider ElectricFacility Expert Small BusinessCloudFixedlinkcisagov2021-12-20
Schneider ElectricMSECurrent software and earlierAffectedlinkcisagov2021-12-20
Schneider ElectricNetBotz750/755Software versions 5.0 through 5.3.0Affectedlinkcisagov2021-12-20
Schneider ElectricNEW630Current software and earlierAffectedlinkcisagov2021-12-20
Schneider ElectricSDK BOMCurrent software and earlierAffectedlinkcisagov2021-12-20
Schneider ElectricSDK-DocgenCurrent software and earlierAffectedlinkcisagov2021-12-20
Schneider ElectricSDK-TNCCurrent software and earlierAffectedlinkcisagov2021-12-20
Schneider ElectricSDK-UMSCurrent software and earlierAffectedlinkcisagov2021-12-20
Schneider ElectricSDK3D2DRendererCurrent software and earlierAffectedlinkcisagov2021-12-20
Schneider ElectricSDK3D360WidgetCurrent software and earlierAffectedlinkcisagov2021-12-20
Schneider ElectricSelect and Config DATACurrent software and earlierAffectedlinkcisagov2021-12-20
Schneider ElectricSNC-APICurrent software and earlierAffectedlinkcisagov2021-12-20
Schneider ElectricSNC-CMMCurrent software and earlierAffectedlinkcisagov2021-12-20
Schneider ElectricSNCSEMTECHCurrent software and earlierAffectedlinkcisagov2021-12-20
Schneider ElectricSPIMV3Current software and earlierAffectedlinkcisagov2021-12-20
Schneider ElectricSWBEditorCurrent software and earlierAffectedlinkcisagov2021-12-20
Schneider ElectricSWBEngineCurrent software and earlierAffectedlinkcisagov2021-12-20
Schneider ElectricWiser by SE platformCloudFixedcisagov2021-12-20
Schweitzer Engineering LaboratoriesUnknownlinkcisagov2021-12-21
SCM ManagerUnknownlinkcisagov2022-01-12
ScreenBeamUnknownlinkcisagov2022-01-12
SDL worldServerUnknownlinkcisagov2022-01-12
Seagull ScientificUnknownlinkcisagov2022-01-12
SecurePointUnknownlinkcisagov2022-01-12
Security OnionUnknownlinkcisagov2022-01-12
SecuronixExtended Detection and Response (XDR)AllAffectedlinkPatching ongoing as of 12/10/2021cisagov2021-12-10
SecuronixNext Gen SIEMAllAffectedlinkPatching ongoing as of 12/10/2021cisagov2021-12-10
SecuronixSecurity Analytics and Operations Platform (SOAR)AllAffectedlinkPatching ongoing as of 12/10/2021cisagov2021-12-10
SecuronixSNYPR ApplicationUnknownlinkcisagov2021-12-10
SecuronixUser and Entity Behavior Analytics(UEBA)AllAffectedlinkPatching ongoing as of 12/10/2021cisagov2021-12-10
SeeburgerUnknownlinkThis advisory is available to customers only and has not been reviewed by CISA.cisagov2022-01-12
SentinelOneUnknownlinkcisagov2022-01-12
SentryUnknownlinkcisagov2022-01-12
SEPUnknownlinkcisagov2022-01-12
Server EyeUnknownlinkcisagov2022-01-12
ServiceNowUnknownlinkcisagov2022-01-12
ServiceTitanServiceTitanCloudFixedlinkcisagov2022-02-07
ShibbolethUnknownlinkcisagov2022-01-12
ShibbolethAll ProductsNot Affectedlinkcisagov2021-12-10
ShopifyUnknownlinkcisagov2022-01-12
SiebelUnknownlinkcisagov2022-01-12
SiemensAffected ProductsUnknownlinkSiemens requests: See pdf for the complete list of affected products, CSAF for automated parsing of datacisagov2021-12-22
SiemensAffected ProductsUnknownlinkSiemens requests: See pdf for the complete list of affected products, CSAF for automated parsing of datacisagov2021-12-19
Siemens EnergyAffected ProductsUnknownlinkSiemens requests: See pdf for the complete list of affected products, CSAF for automated parsing of datacisagov2021-12-21
Siemens EnergyAffected ProductsUnknownlinkSiemens requests: See pdf for the complete list of affected products, CSAF for automated parsing of datacisagov2021-12-20
Siemens EnergyAffected ProductsUnknownlinkSiemens requests: See pdf for the complete list of affected products, CSAF for automated parsing of datacisagov2021-12-16
Siemens HealthineersATELLICA DATA MANAGER v1.1.1 / v1.2.1 / v1.3.1UnknownlinkIf you have determined that your Atellica Data Manager has a “Java communication engine” service, and you require an immediate mitigation, then please contact your Siemens Customer Care Center or your local Siemens technical support representative.cisagov2021-12-22
Siemens HealthineersCENTRALINK v16.0.2 / v16.0.3UnknownlinkIf you have determined that your CentraLink has a “Java communication engine” service, and you require a mitigation, then please contact your Siemens Customer Care Center or your local Siemens technical support representative.cisagov2021-12-22
Siemens HealthineersCios Flow S1 / Alpha / Spin VA30Unknownlinkevaluation ongoingcisagov2021-12-22
Siemens HealthineersCios Select FD/I.I. VA21 / VA21-S3PUnknownlinkevaluation ongoingcisagov2021-12-22
Siemens HealthineersDICOM Proxy VB10AUnknownlinkWorkaround: remove the vulnerable class from the .jar filecisagov2021-12-22
Siemens Healthineersgo.All, Som10 VA20 / VA30 / VA40UnknownlinkWorkaround: In the meantime, we recommend preventing access to port 8090 from other devices by configuration of the hospital network.cisagov2021-12-22
Siemens Healthineersgo.Fit, Som10 VA30UnknownlinkWorkaround: In the meantime, we recommend preventing access to port 8090 from other devices by configuration of the hospital network.cisagov2021-12-22
Siemens Healthineersgo.Now, Som10 VA10 / VA20 / VA30 / VA40UnknownlinkWorkaround: In the meantime, we recommend preventing access to port 8090 from other devices by configuration of the hospital network.cisagov2021-12-22
Siemens Healthineersgo.Open Pro, Som10 VA30 / VA40UnknownlinkWorkaround: In the meantime, we recommend preventing access to port 8090 from other devices by configuration of the hospital network.cisagov2021-12-22
Siemens Healthineersgo.Sim, Som10 VA30 / VA40UnknownlinkWorkaround: In the meantime, we recommend preventing access to port 8090 from other devices by configuration of the hospital network.cisagov2021-12-22
Siemens Healthineersgo.Top, Som10 VA20 / VA20A_SP5 / VA30 / VA40UnknownlinkWorkaround: In the meantime, we recommend preventing access to port 8090 from other devices by configuration of the hospital network.cisagov2021-12-22
Siemens Healthineersgo.Up, Som10 VA10 / VA20 / VA30 / VA40UnknownlinkWorkaround: In the meantime, we recommend preventing access to port 8090 from other devices by configuration of the hospital network.cisagov2021-12-22
Siemens HealthineersMAGNETOM AERA 1,5T, MAGNETOM PRISMA, MAGNETOM PRISMA FIT, MAGNETOM SKYRA 3T NUMARIS/X VA30AUnknownlinkLOG4J is used in the context of the help system. Workaround: close port 8090 for standalone systems. Setup IP whitelisting for "need to access" systems to network port 8090 in case a second console is connected.cisagov2021-12-22
Siemens HealthineersMAGNETOM Altea NUMARIS/X VA20AUnknownlinkLOG4J is used in the context of the help system. Workaround: close port 8090 for standalone systems. Setup IP whitelisting for "need to access" systems to network port 8090 in case a second console is connected.cisagov2021-12-22
Siemens HealthineersMAGNETOM ALTEA, MAGNETOM LUMINA, MAGNETOM SOLA, MAGNETOM VIDA NUMARIS/X VA31AUnknownlinkLOG4J is used in the context of the help system. Workaround: close port 8090 for standalone systems. Setup IP whitelisting for "need to access" systems to network port 8090 in case a second console is connected.cisagov2021-12-22
Siemens HealthineersMAGNETOM Amira NUMARIS/X VA12MUnknownlinkLOG4J is used in the context of the help system. Workaround: close port 8090 for standalone systems. Setup IP whitelisting for "need to access" systems to network port 8090 in case a second console is connected.cisagov2021-12-22
Siemens HealthineersMAGNETOM Free.Max NUMARIS/X VA40UnknownlinkLOG4J is used in the context of the help system. Workaround: close port 8090 for standalone systems. Setup IP whitelisting for "need to access" systems to network port 8090 in case a second console is connected.cisagov2021-12-22
Siemens HealthineersMAGNETOM Lumina NUMARIS/X VA20AUnknownlinkLOG4J is used in the context of the help system. Workaround: close port 8090 for standalone systems. Setup IP whitelisting for "need to access" systems to network port 8090 in case a second console is connected.cisagov2021-12-22
Siemens HealthineersMAGNETOM Sempra NUMARIS/X VA12MUnknownlinkLOG4J is used in the context of the help system. Workaround: close port 8090 for standalone systems. Setup IP whitelisting for "need to access" systems to network port 8090 in case a second console is connected.cisagov2021-12-22
Siemens HealthineersMAGNETOM Sola fit NUMARIS/X VA20AUnknownlinkLOG4J is used in the context of the help system. Workaround: close port 8090 for standalone systems. Setup IP whitelisting for "need to access" systems to network port 8090 in case a second console is connected.cisagov2021-12-22
Siemens HealthineersMAGNETOM Sola NUMARIS/X VA20AUnknownlinkLOG4J is used in the context of the help system. Workaround: close port 8090 for standalone systems. Setup IP whitelisting for "need to access" systems to network port 8090 in case a second console is connected.cisagov2021-12-22
Siemens HealthineersMAGNETOM Vida fit NUMARIS/X VA20AUnknownlinkLOG4J is used in the context of the help system. Workaround: close port 8090 for standalone systems. Setup IP whitelisting for "need to access" systems to network port 8090 in case a second console is connected.cisagov2021-12-22
Siemens HealthineersMAGNETOM Vida NUMARIS/X VA10A* / VA20AUnknownlinkLOG4J is used in the context of the help system. Workaround: close port 8090 for standalone systems. Setup IP whitelisting for "need to access" systems to network port 8090 in case a second console is connected.cisagov2021-12-22
Siemens HealthineersSENSIS DMCC / DMCM / TS / VM / PPWS / DS VD12AUnknownlinkevaluation ongoingcisagov2021-12-22
Siemens HealthineersSomatom Emotion Som5 VC50Unknownlinkevaluation ongoingcisagov2021-12-22
Siemens HealthineersSomatom Scope Som5 VC50Unknownlinkevaluation ongoingcisagov2021-12-22
Siemens HealthineersSyngo Carbon Space VA10A / VA10A-CUT2 / VA20AUnknownlinkWorkaround: remove the vulnerable class from the .jar filecisagov2021-12-22
Siemens HealthineersSyngo MobileViewer VA10AUnknownlinkThe vulnerability will be patch/mitigated in upcoming releases/patches.cisagov2021-12-22
Siemens Healthineerssyngo Plaza VB20A / VB20A_HF01 - HF07 / VB30A / VB30A_HF01 / VB30A_HF02 / VB30B / VB30C / VB30C_HF01 - HF06 / VB30C_HF91UnknownlinkWorkaround: remove the vulnerable class from the .jar filecisagov2021-12-22
Siemens Healthineerssyngo Workflow MLR VB37A / VB37A_HF01 / VB37A_HF02 / VB37B / VB37B_HF01 - HF07 / VB37B_HF93 / VB37B_HF94 / VB37B_HF96UnknownlinkPlease contact your Customer Service to get support on mitigating the vulnerability.cisagov2021-12-22
Siemens Healthineerssyngo.via VB20A / VB20A_HF01 - HF08 / VB20A_HF91 / VB20B / VB30A / VB30A_HF01 - VB30A_HF08 / VB30A_HF91VB30B / VB30B_HF01 / VB40A / VB40A_HF01 - HF02 /VB40B / VB40B_HF01 - HF05 / VB50A / VB50A_CUT / VB50A_D4VB50B / VB50B_HF01 - HF03 / VB60A / VB60A_CUT / VB60A_D4 / VB60A_HF01UnknownlinkWorkaround: remove the vulnerable class from the .jar filecisagov2021-12-22
Siemens Healthineerssyngo.via WebViewer VA13B / VA20A / VA20BUnknownlinkWorkaround: remove the vulnerable class from the .jar filecisagov2021-12-22
Siemens HealthineersX.Ceed Somaris 10 VA40*UnknownlinkWorkaround: In the meantime, we recommend preventing access to port 8090 from other devices by configuration of the hospital network.cisagov2021-12-22
Siemens HealthineersX.Cite Somaris 10 VA30*/VA40*UnknownlinkWorkaround: In the meantime, we recommend preventing access to port 8090 from other devices by configuration of the hospital network.cisagov2021-12-22
Sierra WirelessUnknownlinkcisagov2022-01-12
Sierra WirelessAirVantage and Octave cloud platformsUnknownlinkThese systems do not operate with the specific non-standard configuration required for CVE-2021-25046 and hence were not vulnerable to it.cisagov2022-01-05
Sierra WirelessAM/AMM serversUnknownlinkcisagov2022-01-05
SignaldUnknownlinkcisagov2022-01-12
Silver PeakOrchestrator, Silver Peak GMSUnknownlinkCustomer managed Orchestrator and legacy GMS products are affected by this vulnerability. This includes on-premise and customer managed instances running in public cloud services such as AWS, Azure, Google, or Oracle Cloud. See Corrective Action Required for details about how to mitigate this exploit.cisagov2021-12-14
SingleWireUnknownlinkThis advisory is available to customers only and has not been reviewed by CISAcisagov2022-01-12
SISCOUnknownlinkcisagov2022-01-05
SitecoreUnknownlinkcisagov2022-01-12
SkillableUnknownlinkcisagov2022-01-12
SLF4JUnknownlinkcisagov2022-01-12
SlurmSlurmNot Affectedlinkcisagov2021-12-21
SMA Solar Technology AGUnknownlinkcisagov2022-01-05
SmartBearUnknownlinkcisagov2022-01-12
SmileCDRUnknownlinkcisagov2022-01-12
Sn0mUnknownlinkcisagov2022-01-12
SnakemakeSnakemakeNot Affectedlinkcisagov2021-12-21
Snow SoftwareSnow Commander8.1 to 8.10.2Fixedlinkcisagov2022-01-12
Snow SoftwareVM Access Proxyv3.1 to v3.6Fixedlinkcisagov2022-01-12
SnowflakeUnknownlinkcisagov2022-01-12
SnykCloud PlatformUnknownlinkcisagov2022-01-12
Software AGUnknownlinkcisagov2022-01-12
SolarWindsDatabase Performance Analyzer (DPA)2021.1.x, 2021.3.x, 2022.1.xAffectedlinkFor more information, please see the following KB article: linkcisagov2021-12-23
SolarWindsOrion PlatformUnknownlinkcisagov2021-12-23
SolarWindsServer & Application Monitor (SAM)SAM 2020.2.6 and laterAffectedlinkFor more information, please see the following KB article for the latest details specific to the SAM hotfix: linkcisagov2021-12-23
SonarSourceUnknownlinkcisagov2022-01-12
SonatypeAll ProductsNot AffectedlinkSonatype uses logback as the default logging solution as opposed to log4j. This means our software including Nexus Lifecycle, Nexus Firewall, Nexus Repository OSS and Nexus Repository Pro in versions 2.x and 3.x are NOT affected by the reported log4j vulnerabilities. We still advise keeping your software upgraded at the latest version.cisagov2021-12-29
SonicWallAccess PointsUnknownlinkLog4j2 not used in the SonicWall Access Pointscisagov2021-12-12
SonicWallAnalyticsUnknownlinkUnder Reviewcisagov2021-12-12
SonicWallAnalyzerUnknownlinkUnder Reviewcisagov2021-12-12
SonicWallCapture Client & Capture Client PortalUnknownlinkLog4j2 not used in the Capture Client.cisagov2021-12-12
SonicWallCapture Security ApplianceUnknownlinkLog4j2 not used in the Capture Security appliance.cisagov2021-12-12
SonicWallCASUnknownlinkUnder Reviewcisagov2021-12-12
SonicWallEmail SecurityUnknownlinkES 10.0.11 and earlier versions are impactedcisagov2021-12-17
SonicWallGen5 Firewalls (EOS)UnknownlinkLog4j2 not used in the appliance.cisagov2021-12-12
SonicWallGen6 FirewallsUnknownlinkLog4j2 not used in the appliance.cisagov2021-12-12
SonicWallGen7 FirewallsUnknownlinkLog4j2 not used in the appliance.cisagov2021-12-12
SonicWallGMSUnknownlinkUnder Reviewcisagov2021-12-12
SonicWallMSWUnknownlinkMysonicwall service doesn't use Log4jcisagov2021-12-12
SonicWallNSMUnknownlinkNSM On-Prem and SaaS doesn't use a vulnerable versioncisagov2021-12-12
SonicWallSMA 100UnknownlinkLog4j2 not used in the SMA100 appliance.cisagov2021-12-12
SonicWallSMA 1000UnknownlinkVersion 12.1.0 and 12.4.1 doesn't use a vulnerable versioncisagov2021-12-12
SonicWallSonicCoreUnknownlinkSonicCore doesn't use a Log4j2cisagov2021-12-12
SonicWallSonicWall SwitchUnknownlinkLog4j2 not used in the SonicWall Switch.cisagov2021-12-12
SonicWallWAFUnknownlinkUnder Reviewcisagov2021-12-12
SonicWallWNMUnknownlinkLog4j2 not used in the WNM.cisagov2021-12-12
SonicWallWXAUnknownlinkWXA doesn't use a vulnerable versioncisagov2021-12-12
SophosCloud OptixUnknownlinkUsers may have noticed a brief outage around 12:30 GMT as updates were deployed. There was no evidence that the vulnerability was exploited and to our knowledge no customers are impacted.cisagov2021-12-12
SophosReflexionUnknownlinkReflexion does not run an exploitable configuration.cisagov2021-12-12
SophosSG UTM (all versions)UnknownlinkSophos SG UTM does not use Log4j.cisagov2021-12-12
SophosSG UTM Manager (SUM) (all versions)Not AffectedlinkSUM does not use Log4j.cisagov2021-12-12
SophosSophos CentralUnknownlinkSophos Central does not run an exploitable configuration.cisagov2021-12-12
SophosSophos Firewall (all versions)UnknownlinkSophos Firewall does not use Log4j.cisagov2021-12-12
SophosSophos HomeUnknownlinkSophos Home does not use Log4j.cisagov2021-12-12
SophosSophos MobileUnknownlinkSophos Mobile (in Central, SaaS, and on-premises) does not run an exploitable configuration.cisagov2021-12-12
SophosSophos Mobile EAS Proxy< 9.7.2AffectedlinkThe Sophos Mobile EAS Proxy, running in Traffic Mode, is affected. Customers will need to download and install version 9.7.2, available from Monday December 13, 2021, on the same machine where it is currently running. PowerShell mode is not affected. Customers can download the Standalone EAS Proxy Installer version 9.7.2 from the Sophos website.cisagov2021-12-12
SophosSophos ZTNAUnknownlinkSophos ZTNA does not use Log4j.cisagov2021-12-12
SOS BerlinUnknownlinkcisagov2022-01-12
Spacelabs HealthcareABPNot Affectedlinkcisagov2022-01-05
Spacelabs HealthcareCardioExpressNot Affectedlinkcisagov2022-01-05
Spacelabs HealthcareDM3 and DM4 MonitorsUnknownlinkcisagov2022-01-05
Spacelabs HealthcareEclipse ProUnknownlinkcisagov2022-01-05
Spacelabs HealthcareEVOUnknownlinkcisagov2022-01-05
Spacelabs HealthcareIntesys Clinical Suite (ICS)Unknownlinkcisagov2022-01-05
Spacelabs HealthcareIntesys Clinical Suite (ICS) Clinical Access WorkstationsUnknownlinkcisagov2022-01-05
Spacelabs HealthcareLifescreen ProUnknownlinkcisagov2022-01-05
Spacelabs HealthcarePathfinder SLUnknownlinkcisagov2022-01-05
Spacelabs HealthcareQubeNot Affectedlinkcisagov2022-01-05
Spacelabs HealthcareQube MiniNot Affectedlinkcisagov2022-01-05
Spacelabs HealthcareSafeNSound4.3.1FixedlinkVersion >4.3.1 - Not Affectedcisagov2022-01-05
Spacelabs HealthcareSentinelUnknownlinkcisagov2022-01-05
Spacelabs HealthcareSpacelabs CloudUnknownlinkcisagov2022-01-05
Spacelabs HealthcareUltraview SLNot Affectedlinkcisagov2022-01-05
Spacelabs HealthcareXhibit Telemetry Receiver (XTR)Not Affectedlinkcisagov2022-01-05
Spacelabs HealthcareXhibit, XC4Not Affectedlinkcisagov2022-01-05
Spacelabs HealthcareXprezzNetNot Affectedlinkcisagov2022-01-05
Spacelabs HealthcareXprezzonNot Affectedlinkcisagov2022-01-05
SpambrellaUnknownlinkcisagov2022-01-12
SpigotUnknownlinkcisagov2022-01-12
SplunkData Stream ProcessorDSP 1.0.x, DSP 1.1.x, DSP 1.2.xAffectedlinkcisagov2021-12-30
SplunkIT Essentials Work App ID 54034.11, 4.10.x (Cloud only), 4.9.xAffectedlinkcisagov2021-12-30
SplunkIT Service Intelligence (ITSI) App ID 18414.11.0, 4.10.x (Cloud only), 4.9.x, 4.8.x (Cloud only), 4.7.x, 4.6.x, 4.5.xAffectedlinkcisagov2021-12-30
SplunkSplunk Add-On for Java Management Extensions App ID 26475.2.0 and olderAffectedlinkcisagov2021-12-30
SplunkSplunk Add-On for Tomcat App ID 29113.0.0 and olderAffectedlinkcisagov2021-12-30
SplunkSplunk Application Performance MonitoringCurrentAffectedlinkcisagov2021-12-30
SplunkSplunk Connect for KafkaAll versions prior to 2.0.4Affectedlinkcisagov2021-12-30
SplunkSplunk Enterprise (including instance types like Heavy Forwarders)All supported non-Windows versions of 8.1.x and 8.2.x only if DFS is used. See Removing Log4j from Splunk Enterprise below for guidance on unsupported versions.Affectedlinkcisagov2021-12-30
SplunkSplunk Enterprise Amazon Machine Image (AMI)See Splunk EnterpriseAffectedlinkcisagov2021-12-30
SplunkSplunk Enterprise Docker ContainerSee Splunk EnterpriseAffectedlinkcisagov2021-12-30
SplunkSplunk Infrastructure MonitoringCurrentAffectedlinkcisagov2021-12-30
SplunkSplunk Log ObserverCurrentAffectedlinkcisagov2021-12-30
SplunkSplunk Logging Library for Java1.11.0 and olderAffectedlinkcisagov2021-12-30
SplunkSplunk On-call / VictorOpsCurrentAffectedlinkcisagov2021-12-30
SplunkSplunk OVA for VMWare App ID 32164.0.3 and olderAffectedlinkcisagov2021-12-30
SplunkSplunk OVA for VMWare Metrics App ID 50964.2.1 and olderAffectedlinkcisagov2021-12-30
SplunkSplunk Real User MonitoringCurrentAffectedlinkcisagov2021-12-30
SplunkSplunk Splunk Add-On for JBoss App ID 29543.0.0 and olderAffectedlinkcisagov2021-12-30
SplunkSplunk SyntheticsCurrentAffectedlinkcisagov2021-12-30
SplunkSplunk UBA OVA Software5.0.3a, 5.0.0Affectedlinkcisagov2021-12-30
SplunkSplunk VMWare OVA for ITSI App ID 47601.1.1 and olderAffectedlinkcisagov2021-12-30
Sprecher AutomationUnknownlinkcisagov2022-01-12
SpringSpring BootUnknownlinkSpring Boot users are only affected by this vulnerability if they have switched the default logging system to Log4J2cisagov2022-01-12
Spring BootUnknownlinkcisagov2022-01-12
StarDogUnknownlinkcisagov2022-01-12
STERISAdvantageUnknownlinkcisagov2021-12-22
STERISAdvantage PlusUnknownlinkcisagov2021-12-22
STERISAMSCO 2000 SERIES WASHER DISINFECTORSUnknownlinkcisagov2021-12-22
STERISAMSCO 3000 SERIES WASHER DISINFECTORSUnknownlinkcisagov2021-12-22
STERISAMSCO 400 MEDIUM STEAM STERILIZERUnknownlinkcisagov2021-12-22
STERISAMSCO 400 SMALL STEAM STERILIZERSUnknownlinkcisagov2021-12-22
STERISAMSCO 5000 SERIES WASHER DISINFECTORSUnknownlinkcisagov2021-12-22
STERISAMSCO 600 MEDIUM STEAM STERILIZERUnknownlinkcisagov2021-12-22
STERISAMSCO 7000 SERIES WASHER DISINFECTORSUnknownlinkcisagov2021-12-22
STERISAMSCO CENTURY MEDIUM STEAM STERILIZERUnknownlinkcisagov2021-12-22
STERISAMSCO CENTURY SMALL STEAM STERILIZERUnknownlinkcisagov2021-12-22
STERISAMSCO EAGLE 3000 SERIES STAGE 3 STEAM STERILIZERSUnknownlinkcisagov2021-12-22
STERISAMSCO EVOLUTION FLOOR LOADER STEAM STERILIZERUnknownlinkcisagov2021-12-22
STERISAMSCO EVOLUTION MEDIUM STEAM STERILIZERUnknownlinkcisagov2021-12-22
STERISCanexis 1.0Unknownlinkcisagov2021-12-22
STERISCELERITY HP INCUBATORUnknownlinkcisagov2021-12-22
STERISCELERITY STEAM INCUBATORUnknownlinkcisagov2021-12-22
STERISCER OptimaUnknownlinkcisagov2021-12-22
STERISClarity SoftwareUnknownlinkcisagov2021-12-22
STERISConnect SoftwareUnknownlinkcisagov2021-12-22
STERISConnectAssure TechnologyUnknownlinkcisagov2021-12-22
STERISConnectoHISUnknownlinkcisagov2021-12-22
STERISCS-iQ Sterile Processing WorkflowUnknownlinkcisagov2021-12-22
STERISDSD EdgeUnknownlinkcisagov2021-12-22
STERISDSD-201,Unknownlinkcisagov2021-12-22
STERISEndoDryUnknownlinkcisagov2021-12-22
STERISEndoraUnknownlinkcisagov2021-12-22
STERISHarmony iQ Integration SystemsUnknownlinkcisagov2021-12-22
STERISHarmony iQ Perspectives Image Management SystemUnknownlinkcisagov2021-12-22
STERISHexaVueUnknownlinkcisagov2021-12-22
STERISHexaVue Integration SystemUnknownlinkcisagov2021-12-22
STERISIDSS Integration SystemUnknownlinkcisagov2021-12-22
STERISRapidAERUnknownlinkcisagov2021-12-22
STERISReadyTrackerUnknownlinkcisagov2021-12-22
STERISRealView Visual Workflow Management SystemUnknownlinkcisagov2021-12-22
STERISRELIANCE 444 WASHER DISINFECTORUnknownlinkcisagov2021-12-22
STERISRELIANCE SYNERGY WASHER DISINFECTORUnknownlinkcisagov2021-12-22
STERISRELIANCE VISION 1300 SERIES CART AND UTENSIL WASHER DISINFECTORSUnknownlinkcisagov2021-12-22
STERISRELIANCE VISION MULTI- CHAMBER WASHER DISINFECTORUnknownlinkcisagov2021-12-22
STERISRELIANCE VISION SINGLE CHAMBER WASHER DISINFECTORUnknownlinkcisagov2021-12-22
STERISRenatronUnknownlinkcisagov2021-12-22
STERISScopeBuddy+Unknownlinkcisagov2021-12-22
STERISSecureCare ProConnect Technical Support ServicesUnknownlinkcisagov2021-12-22
STERISSituational Awareness for Everyone Display (S.A.F.E.)Unknownlinkcisagov2021-12-22
STERISSPM Surgical Asset Tracking SoftwareUnknownlinkcisagov2021-12-22
STERISSYSTEM 1 endo LIQUID CHEMICAL STERILANT PROCESSING SYSTEMUnknownlinkcisagov2021-12-22
STERISV-PRO 1 LOW TEMPERATURE STERILIZATION SYSTEMUnknownlinkcisagov2021-12-22
STERISV-PRO 1 PLUS LOW TEMPERATURE STERILIZATION SYSTEMUnknownlinkcisagov2021-12-22
STERISV-PRO MAX 2 LOW TEMPERATURE STERILIZATION SYSTEMUnknownlinkcisagov2021-12-22
STERISV-PRO MAX LOW TEMPERATURE STERILIZATION SYSTEMUnknownlinkcisagov2021-12-22
STERISV-PRO S2 LOW TEMPERATURE STERILIZATION SYSTEMUnknownlinkcisagov2021-12-22
STERISVERIFY INCUBATOR FOR ASSERT SELF-CONTAINED BIOLOGICAL INDICATORSUnknownlinkcisagov2021-12-22
Sterling Order IBMUnknownlinkcisagov2022-01-12
StoragementUnknownlinkcisagov2022-01-12
StormShieldUnknownlinkcisagov2022-01-12
StrangeBee TheHive & CortexUnknownlinkcisagov2022-01-12
StratodeskUnknownlinkcisagov2022-01-12
StrimziUnknownlinkcisagov2022-01-12
StripeUnknownlinkcisagov2022-01-12
StyraUnknownlinkcisagov2022-01-12
SumologicUnknownlinkcisagov2022-01-12
SumoLogicUnknownlinkcisagov2022-01-12
Superna EYEGLASSUnknownlinkcisagov2022-01-12
Suprema IncUnknownlinkcisagov2022-01-12
SUSEUnknownlinkcisagov2022-01-12
SweepwidgetUnknownlinkcisagov2022-01-12
SwyxUnknownlinkcisagov2022-01-12
Synchro MSPUnknownlinkcisagov2022-01-12
SyncplifyUnknownlinkcisagov2022-01-12
SynologyUnknownlinkcisagov2022-01-12
SynopsysUnknownlinkcisagov2022-01-12
SyntevoUnknownlinkcisagov2022-01-12
SysAidUnknownlinkcisagov2022-01-12
SysdigUnknownlinkcisagov2022-01-12