CISA Log4j (CVE-2021-44228) Affected Vendor & Software List

October 12, 2022 ยท View on GitHub

0-9 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Status Descriptions

StatusDescription
UnknownStatus unknown. Default choice.
AffectedReported to be affected by CVE-2021-44228.
Not AffectedReported to NOT be affected by CVE-2021-44228 and no further action necessary.
FixedPatch and/or mitigations available (see provided links).
Under InvestigationVendor investigating status.

Software List

This list has been populated using information from the following sources:

  • Kevin Beaumont
  • SwitHak
  • National Cyber Security Centre - Netherlands (NCSC-NL)

NOTE: This file is automatically generated. To submit updates, please refer to CONTRIBUTING.md.

VendorProductAffected VersionsPatched VersionsStatusVendor LinksNotesReferencesReporterLast Updated
WAGOWAGO Smart Script4.2.x < 4.8.1.3Fixedlinkcisagov2021-12-17
WallarmAllUnknownlinkcisagov2022-01-12
WallixAccess ManagerFixedlinkCustomer Portal for patch found in advisory. This patch is available to customer only and has not been reviewed by CISA.cisagov2022-02-03
Wasp Barcode technologiesAllUnknownlinkcisagov2022-01-12
WatcherAllNot Affectedlinkcisagov2022-01-12
WatchGuardAuthPointCloudFixedlinkcisagov2022-01-12
WatchGuardDimensionNot Affectedlinkcisagov2022-01-12
WatchGuardEDPR and Panda AD360Not Affectedlinkcisagov2022-01-12
WatchGuardFireboxNot Affectedlinkcisagov2022-01-12
WatchGuardSystem Manager, Dimension, and Panda AD360Not Affectedlinkcisagov2022-01-12
WatchGuardThreat Detection and ResponseCloudFixedlinkcisagov2022-01-12
WatchGuardWi-Fi CloudCloudFixedlinkcisagov2022-01-12
Western DigitalUnknownlinkcisagov2022-01-12
WIBU SystemsCodeMeter Cloud Lite2.2 and priorFixedlinkcisagov2021-12-22
WIBU SystemsCodeMeter Keyring for TIA Portal1.30 and priorFixedlinkOnly the Password Manager is affectedcisagov2021-12-22
WildFlyAllNot Affectedlinkcisagov2022-01-21
Wind RiverLTS17Not Affectedlinkcisagov2022-01-21
Wind RiverLTS18Not Affectedlinkcisagov2022-01-21
Wind RiverLTS19Not Affectedlinkcisagov2022-01-21
Wind RiverLTS21Not Affectedlinkcisagov2022-01-12
Wind RiverWRL-6Not AffectedlinkThe Wind River Linux Product Versions 8.0 and prior contains the log4j1.2 and JMSAppender components, however, JMSAppender is deactivated in the release package and not affected by CVE-2021-4104 customers are advised to NOT manually activate the JMSAppender component.cisagov2022-01-21
Wind RiverWRL-7Not AffectedlinkThe Wind River Linux Product Versions 8.0 and prior contains the log4j1.2 and JMSAppender components, however, JMSAppender is deactivated in the release package and not affected by CVE-2021-4104 customers are advised to NOT manually activate the JMSAppender component.cisagov2022-01-21
Wind RiverWRL-8Not AffectedlinkThe Wind River Linux Product Versions 8.0 and prior contains the log4j1.2 and JMSAppender components, however, JMSAppender is deactivated in the release package and not affected by CVE-2021-4104 customers are advised to NOT manually activate the JMSAppender component.cisagov2022-01-21
Wind RiverWRL-9Not Affectedlinkcisagov2022-01-21
WireSharkAllNot Affectedlinkcisagov2021-12-15
WistiaAllUnknownlinkcisagov2022-01-12
WitFooPrecinct6.xFixedlinkWitFoo Streamer & Apache Kafka Docker containers are/were vulnerable. See advisory.cisagov2022-01-12
WordPressAllNot Affectedlinkcisagov2022-01-12
WorksphereAllUnknownlinkcisagov2022-01-12
WowzaStreaming Engine4.7.8, 4.8.xFixedlinkcisagov2022-01-12
WSO2API Manager>= 3.0.0FixedlinkA temporary mitigation is available while vendor works on update.cisagov2022-01-26
WSO2API Manager Analytics>= 2.6.0FixedlinkA temporary mitigation is available while vendor works on update.cisagov2022-01-26
WSO2Enterprise Integrator>= 6.1.0FixedlinkA temporary mitigation is available while vendor works on update.cisagov2022-01-26
WSO2Enterprise Integrator Analytics>= 6.6.0FixedlinkA temporary mitigation is available while vendor works on update.cisagov2022-01-26
WSO2Identity Server>= 5.9.0FixedlinkA temporary mitigation is available while vendor works on update.cisagov2022-01-26
WSO2Identity Server Analytics>= 5.7.0FixedlinkA temporary mitigation is available while vendor works on update.cisagov2022-01-26
WSO2Identity Server as Key Manager>= 5.9.0FixedlinkA temporary mitigation is available while vendor works on update.cisagov2022-01-26
WSO2Micro Gateway>= 3.2.0FixedlinkA temporary mitigation is available while vendor works on update.cisagov2022-01-26
WSO2Micro Integrator>= 1.1.0FixedlinkA temporary mitigation is available while vendor works on update.cisagov2022-01-26
WSO2Micro Integrator Dashboard>= 4.0.0FixedlinkA temporary mitigation is available while vendor works on update.cisagov2022-01-26
WSO2Micro Integrator Monitoring Dashboard>= 1.0.0FixedlinkA temporary mitigation is available while vendor works on update.cisagov2022-01-26
WSO2Open Banking AM>= 2.0.0FixedlinkA temporary mitigation is available while vendor works on update.cisagov2022-01-26
WSO2Open Banking BI>= 1.3.0FixedlinkA temporary mitigation is available while vendor works on update.cisagov2022-01-26
WSO2Open Banking KM>= 2.0.0FixedlinkA temporary mitigation is available while vendor works on update.cisagov2022-01-26
WSO2Stream Integrator>= 1.0.0FixedlinkA temporary mitigation is available while vendor works on update.cisagov2022-01-26
WSO2Stream Integrator Tooling>= 1.0.0FixedlinkA temporary mitigation is available while vendor works on update.cisagov2022-01-26
WSO2Stream Processor>= 4.0.0FixedlinkA temporary mitigation is available while vendor works on update.cisagov2022-01-26