Skip to content
This repository has been archived by the owner on Jun 16, 2022. It is now read-only.

Latest commit

 

History

History
213 lines (210 loc) · 41.1 KB

software_list_r.md

File metadata and controls

213 lines (210 loc) · 41.1 KB

List of software (un)affected by the log4shell CVEs

About this list

0-9 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

R

Supplier Product Version (see Status) Status CVE-2021-4104 Status CVE-2021-44228 Status CVE-2021-45046 Status CVE-2021-45105 Notes Links
R All 4.1.1 Not vuln Not vuln Not vuln Not vuln source
R2ediviewer All R2ediviewer Link
Radware All Radware Support Link
Rapid7 AlcidekArt, kAdvisor, and kAudit on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 AppSpider Enterprise on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 AppSpider Pro on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 Insight Agent on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 InsightAppSec Scan Engine on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 InsightCloudSec/DivvyCloud on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 InsightConnect Orchestrator on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 InsightIDR Network Sensor on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 InsightIDR/InsightOps Collector & Event Sources on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 InsightOps DataHub 2.0.1 Fix source Fix
Rapid7 InsightOps non-Java logging libraries on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 InsightOps r77insight_java Logging Libary 3.0.9 Fix source
Rapid7 InsightOps r7insight_java logging library <=3.0.8 Not vuln Fix Upgrade r7insight_java to 3.0.9 Rapid7 Statement
Rapid7 InsightVM Kubernetes Monitor on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 InsightVM/Nexpose on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 InsightVM/Nexpose Console on-prem Not vuln Not vuln Not vuln Not vuln Installations of the InsightVM/Nexpose have “log4j-over-slf4j-1.7.7.jar” packaged in them. This is a different library than log4j-core and is not vulnerable to Log4Shell. Rapid7 Statement
Rapid7 InsightVM/Nexpose Engine on-prem Not vuln Not vuln Not vuln Not vuln Installations of the InsightVM/Nexpose have “log4j-over-slf4j-1.7.7.jar” packaged in them. This is a different library than log4j-core and is not vulnerable to Log4Shell. Rapid7 Statement
Rapid7 IntSights virtual appliance on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 Logentries DataHub 1.2.0.822 Fix source Windows Fix Linux Fix
Rapid7 Logentries le_java Logging Libary All Vulnerable Migrate to v3.0.9 of r7insight_java source
Rapid7 Logentries le_java logging library All versions: this is a deprecated component Not vuln Fix Migrate to version 3.0.9 of r7insight_java Rapid7 Statement
Rapid7 Metasploit Framework on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 Metasploit Pro on-prem Not vuln Not vuln Not vuln Not vuln Metasploit Pro ships with log4j but has specific configurations applied to it that mitigate Log4Shell. A future update will contain a fully patched version of log4j. Rapid7 Statement
Rapid7 tCell Java Agent on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 Velociraptor on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Raritan All Raritan Support Link
Ravelin All Ravelin Link
Real-Time Innovations (RTI) Distributed Logger Not vuln Not vuln Not vuln Not vuln RTI Statement
Real-Time Innovations (RTI) Recording Console Not vuln Not vuln Not vuln Not vuln RTI Statement
Real-Time Innovations (RTI) RTI Administration Console Not vuln Not vuln Not vuln Not vuln RTI Statement
Real-Time Innovations (RTI) RTI Code Generator Not vuln Not vuln Not vuln Not vuln RTI Statement
Real-Time Innovations (RTI) RTI Code Generator Server Not vuln Not vuln Not vuln Not vuln RTI Statement
Real-Time Innovations (RTI) RTI Micro Application Generator (MAG) as part of RTI Connext Micro 3.0.0, 3.0.1, 3.0.2, 3.0.3 Vulnerable RTI Statement
Real-Time Innovations (RTI) RTI Micro Application Generator (MAG) as part of RTI Connext Professional 6.0.0 and 6.0.1 Vulnerable RTI Statement
Real-Time Innovations (RTI) RTI Monitor Not vuln Not vuln Not vuln Not vuln RTI Statement
Red Hat A-MQ Clients 2 Not vuln source
Red Hat build of Quarkus Not vuln source
Red Hat CodeReady Studio 12.21.0 Not vuln Fix CRS 12.21.1 Patch CVE-2021-44228- Red Hat Customer Portal
Red Hat CodeReady Studio 12 Vulnerable source
Red Hat Data Grid 8 Not vuln Fix RHSA-2021:5132 CVE-2021-44228- Red Hat Customer Portal
Red Hat Data Grid 8 8.2.2 Not vuln Fix RHSA-2021:5132 source
Red Hat Decision Manager 7 Not vuln Not vuln Not vuln Not vuln CVE-2021-44228- Red Hat Customer Portal
Red Hat Descision Manager 7 Vulnerable source
Red Hat Enterprise Linux 6 Not vuln Not vuln Not vuln Not vuln CVE-2021-44228- Red Hat Customer Portal
Red Hat Enterprise Linux 7 Not vuln Not vuln Not vuln Not vuln CVE-2021-44228- Red Hat Customer Portal
Red Hat Enterprise Linux 8 Not vuln Not vuln Not vuln Not vuln CVE-2021-44228- Red Hat Customer Portal
Red Hat Integration Camel K Vulnerable source
Red Hat Integration Camel Quarkus Vulnerable source
Red Hat JBoss A-MQ Streaming 1.6.5 Not vuln Fix RHSA-2021:5133 source
Red Hat JBoss Enterprise Application Platform 7 Not vuln Fix Maven Patch - Affects only the Mavenized distribution. Container, Zip and RPM distro aren't affected. CVE-2021-44228- Red Hat Customer Portal
Red Hat JBoss Enterprise Application Platform 6 Not vuln source
Red Hat JBoss Enterprise Application Platform Expansion Pack Not vuln source
Red Hat JBoss Fuse 7 7.10.0 Not vuln Fix RHSA-2021:5134 source
Red Hat log4j-core Not vuln Not vuln Not vuln Not vuln CVE-2021-44228- Red Hat Customer Portal
Red Hat OpenShift Application Runtimes 1.0 n.a. (see notes) Not vuln Fix RHSA-2021:5093 - Red Hat build of Eclipse Vert.x 4.1.5 SP1 source
Red Hat OpenShift Container Platform 3.11 openshift3/ose-logging-elasticsearch5 3.11.z Not vuln Fix RHSA-2021:5094 source
Red Hat OpenShift Container Platform 4 openshift4/ose-logging-elasticsearch6 4.6.z Not vuln Fix RHSA-2021:5106 source
Red Hat OpenShift Container Platform 4 openshift4/ose-metering-hive 4.8.z Not vuln Fix RHSA-2021:5108 source
Red Hat OpenShift Container Platform 4.6 openshift4/ose-metering-presto 4.6.52 Not vuln Fix RHSA-2021:5141 source
Red Hat OpenShift Container Platform 4.7 openshift4/ose-metering-presto 4.7.40 Not vuln Fix RHSA-2021:5107 source
Red Hat OpenShift Container Platform 4.8 openshift4/ose-metering-presto 4.8.24 Not vuln Fix RHSA-2021:5148 source
Red Hat OpenShift Logging 5.0 openshift-logging/elasticsearch6-rhel8 5.0.10 Not vuln Fix RHSA-2021:5137 source
Red Hat OpenShift Logging 5.0 openshift-logging/elasticsearch6-rhel8 5.3.1 Not vuln Fix RHSA-2021:5129 source
Red Hat OpenShift Logging 5.1 openshift-logging/elasticsearch6-rhel8 5.1.5 Not vuln Fix RHSA-2021:5128 source
Red Hat OpenShift Logging 5.2 openshift-logging/elasticsearch6-rhel8 5.2.4 Not vuln Fix RHSA-2021:5127 source
Red Hat OpenStack Platform 13 (Queens) opendaylight Vulnerable source
Red Hat Process Automation 7 Not vuln Fix Maven Patch - Affects only the Mavenized distribution. Container, Zip and RPM distro aren't affected. CVE-2021-44228- Red Hat Customer Portal
Red Hat Process Automation 7 Vulnerable source
Red Hat Satellite 5 Not vuln Not vuln Not vuln Not vuln CVE-2021-44228- Red Hat Customer Portal
Red Hat Single Sign-On 7 Not vuln Not vuln Not vuln Not vuln CVE-2021-44228- Red Hat Customer Portal
Red Hat Single Sign-On 7 Not vuln source
Red Hat Spacewalk Not vuln Not vuln Not vuln Not vuln CVE-2021-44228- Red Hat Customer Portal
Red Hat Vert.X 4 Not vuln Fix RHSA-2021:5093 CVE-2021-44228- Red Hat Customer Portal
Red Hat Virtualization 4 Not vuln source
Red Hat OpenShift Container Platform 3.11 openshift3/ose-logging-elasticsearch5 Not vuln Fix RHSA-2021:5094 CVE-2021-44228- Red Hat Customer Portal
Red Hat OpenShift Container Platform 4 openshift4/ose-logging-elasticsearch6 Not vuln Fix Please refer to Red Hat Customer Portal to find the left errata for your version. CVE-2021-44228- Red Hat Customer Portal
Red Hat OpenShift Container Platform 4 openshift4/ose-metering-hive Not vuln Fix Please refer to Red Hat Customer Portal to find the left errata for your version. CVE-2021-44228- Red Hat Customer Portal
Red Hat OpenShift Container Platform 4 openshift4/ose-metering-presto Not vuln Fix Please refer to Red Hat Customer Portal to find the left errata for your version. CVE-2021-44228- Red Hat Customer Portal
Red Hat OpenShift Logging logging-elasticsearch6-container Not vuln Fix Please refer to Red Hat Customer Portal to find the left errata for your version. CVE-2021-44228- Red Hat Customer Portal
Red Hat OpenStack Platform 13 (Queens) opendaylight Vulnerable End of Life CVE-2021-44228- Red Hat Customer Portal
Red Hat Software Collections rh-java-common-log4j Not vuln Not vuln Not vuln Not vuln CVE-2021-44228- Red Hat Customer Portal
Red Hat Software Collections rh-maven35-log4j12 Not vuln Not vuln Not vuln Not vuln CVE-2021-44228- Red Hat Customer Portal
Red Hat Software Collections rh-maven36-log4j12 Not vuln Not vuln Not vuln Not vuln CVE-2021-44228- Red Hat Customer Portal
Red5Pro All Red5Pro Link
Redgate Flyway All Not vuln Only vulnerable when using non-default config. source
Redis Enterprise & Open Source All Not vuln Redis Enterprise and Open Source Redis (self-managed software product) does not use Java and is therefore not impacted by this vulnerability source
Redis Jedis 3.7.1, 4.0.0-rc2 Not vuln Fix Jedis uses the affected library in test suites only. source
Reiner SCT All Reiner SCT Forum
ReportURI All ReportURI Link
ResMed AirView Not vuln source
ResMed myAir Not vuln source
Respondus All This advisory is available to customers only and has not been reviewed by CISA Respondus Support Link
Revenera FlexNet Publisher 64-bit License Server Manager Vulnerable Vulnerable source
Revenera / Flexera All Revenera / Flexera Community Link
Ricoh Commercial & Industrial Printing - Garment Printers Not vuln source
Ricoh Commercial & Industrial Printing - Production Printers Investigation source
Ricoh Office Products - Digital Duplicators Not vuln source
Ricoh Office Products - FAX Not vuln source
Ricoh Office Products - Interactive Whiteboards Not vuln source
Ricoh Office Products - Multifunction Printers/Copiers - Black & White MFP Not vuln source
Ricoh Office Products - Multifunction Printers/Copiers - Color MFP Not vuln source
Ricoh Office Products - Multifunction Printers/Copiers - Wide Format MFP Not vuln source
Ricoh Office Products - Printers - Black & White Laser Printers Not vuln source
Ricoh Office Products - Printers - Color Laser Printers Not vuln source
Ricoh Office Products - Printers - Gel Jet Printers Not vuln source
Ricoh Office Products - Printers - Handy Printers Not vuln source
Ricoh Office Products - Printers - Printer based MFP Not vuln source
Ricoh Office Products - Projectors Not vuln source
Ricoh Office Products - Video Conferencing Not vuln source
Ricoh Software & Solutions - @Remote Connector NX Not vuln source
Ricoh Software & Solutions - Card Authentication Package Series Not vuln source
Ricoh Software & Solutions - Certificate Enrolment Service Not vuln source
Ricoh Software & Solutions - Device Manager NX Accounting Not vuln source
Ricoh Software & Solutions - Device Manager NX Enterprise Not vuln source
Ricoh Software & Solutions - Device Manager NX Lite Not vuln source
Ricoh Software & Solutions - Device Manager NX Pro Not vuln source
Ricoh Software & Solutions - Docuware Not vuln source
Ricoh Software & Solutions - Enhanced Locked Print Series Not vuln source
Ricoh Software & Solutions - GlobalScan NX Not vuln source
Ricoh Software & Solutions - Intelligent Barcode Solution Not vuln source
Ricoh Software & Solutions - myPrint Not vuln source
Ricoh Software & Solutions - Printer Driver Packager NX Not vuln source
Ricoh Software & Solutions - Ricoh Print Management Cloud Not vuln source
Ricoh Software & Solutions - Ricoh Smart Integration (RSI) applications Not vuln source
Ricoh Software & Solutions - Ricoh Smart Integration (RSI) Platform and its applications Not vuln source
Ricoh Software & Solutions - Ricoh Streamline NX V2 Not vuln source
Ricoh Software & Solutions - Ricoh Streamline NX V3 Not vuln source
Ricoh Software & Solutions - Scan Workflow Navigator Not vuln source
Ricoh Software & Solutions - Streamline NX Share Not vuln source
RingCentral All RingCentral Security Bulletin
Riverbed AppResponse11 Not vuln source
Riverbed Aternity Investigation See source for latest updates source
Riverbed Client Accelerator Controllers and Client Accelerator (aka SteelCentral Controller for SteelHead Mobile and SteelHead Mobile) Not vuln source
Riverbed Flow Gateway Not vuln Not vuln Not vuln Not vuln source
Riverbed FlowTraq Not vuln Not vuln Not vuln Not vuln source
Riverbed Modeler Investigation source
Riverbed NetAuditor Desktop Investigation source
Riverbed NetAuditor Web Not vuln Not vuln Not vuln Not vuln source
Riverbed NetCollector Investigation source
Riverbed NetExpress Investigation source
Riverbed NetIM 1.x Not vuln Not vuln Not vuln Not vuln source
Riverbed NetIM 2.x Vulnerable Patches planned source
Riverbed NetIM Test Engine Not vuln Not vuln Not vuln Not vuln source
Riverbed NetPlanner Not vuln Not vuln Not vuln Not vuln source
Riverbed NetProfiler Not vuln Not vuln Not vuln Not vuln source
Riverbed Packet Analyzer Not vuln source
Riverbed Packet Trace Warehouse Not vuln source
Riverbed Portal 1.x Vulnerable Includes Log4j 2.2 source
Riverbed Portal 3.x Vulnerable Includes Log4j 2.13 source
Riverbed SaaS Accelerator Not vuln source
Riverbed Scon CX Not vuln Not vuln Not vuln Not vuln source
Riverbed Scon EX Analytics Vulnerable Patches planned source
Riverbed Scon EX Director Vulnerable Patches planned source
Riverbed Scon EX FlexVNF Not vuln Not vuln Not vuln Not vuln source
Riverbed SteelCentral Controller for SteelHead Not vuln source
Riverbed SteelFusion Edge Not vuln Not vuln Not vuln Not vuln source
Riverbed SteelFusionCore (appliance, virtual) Not vuln Not vuln Not vuln Not vuln source
Riverbed SteelHead CX (appliance, virtual, cloud) Not vuln source
Riverbed SteelHead Interceptor Not vuln source
Riverbed Transaction Analyzer Investigation source
Riverbed Transaction Analyzer Agents Not vuln Not vuln Not vuln Not vuln Log4j not in use source
Riverbed UCExpert Vulnerable source
Riverbed WinSec Controller for SteelHead (WSC) Not vuln source
RocketChat All All Not vuln source
Rockwell Automation Data Scheduler Not vuln source
Rockwell Automation FactoryTalk Analytics DataFlowML 4.00.01 Fix source
Rockwell Automation FactoryTalk Analytics DataView 3.03.01 Fix source
Rockwell Automation FactoryTalk Analytics Information Platform Not vuln source
Rockwell Automation FactoryTalk Augmented Modeler Not vuln source
Rockwell Automation Fiix CMMS core V5 Not vuln Fix Fix Fix product has been updated; no user action required source
Rockwell Automation Firewall Managed Support - Cisco Firepower Thread Defense 6.2.3 – 7.1.0 Workaround Follow the mitigation instructions outlined by Cisco in CSCwa46963 source
Rockwell Automation Industrial Data Center Gen 1, Gen 2, Gen 3, Gen 3.5 Not vuln Workaround Follow the mitigation instructions outlined by VMware in VMSA-2021-0028 source
Rockwell Automation MES EIG 3.03.00 Vulnerable Product discontinued. Customers should upgrade to EIG Hub if possible or work with their local representatives about alternative solutions. source
Rockwell Automation Plex Industrial IoT Not vuln Fix Fix Fix product has been updated; no user action required source
Rockwell Automation VersaVirtual Series A Not vuln Workaround Follow the mitigation instructions outlined by VMware in VMSA-2021-0028 source
Rockwell Automation Warehouse Management 4.02.03 Not vuln Fix source
Rollbar All Rollbar Blog Post
Rosette.com All Rosette.com Support Link
RSA NetWitness Orchestrator >= 6.0 Not vuln Workaround Mitigation for the ThreatConnect Application server is available, no impact described source
RSA NetWitness Platform 11.4 Not vuln Workaround It is theoretically possible to exploit the vulnerability to gain shell access to the NetWitness Platform source
RSA NetWitness Platform >= 11.5 Not vuln Workaround It is possible to leak system configuration data source
RSA SecurID Authentication Manager Not vuln Version 8.6 Patch 1 contains a version of log4j that is vulnerable, but this vulnerability is not exploitable. source
RSA SecurID Authentication Manager Prime Not vuln source
RSA SecurID Authentication Manager WebTier Not vuln source
RSA SecurID Governance and Lifecycle Not vuln Not vuln Not vuln Not vuln
RSA SecurID Governance and Lifecycle (SecurID G&L) Not vuln source
RSA SecurID Governance and Lifecycle Cloud Not vuln Not vuln Not vuln Not vuln
RSA SecurID Governance and Lifecycle Cloud (SecurID G&L Cloud) Not vuln source
RSA SecurID Identity Router Not vuln Not vuln Not vuln Not vuln
RSA SecurID Identity Router (On-Prem component of Cloud Authentication Service) Not vuln source
RSA Netwitness All RSA Netwitness Community Link
Rstudioapi All 0.13 Not vuln Not vuln Not vuln Not vuln source
Rubrik All This advisory is available to customers only and has not been reviewed by CISA Rubrik Support Link
Ruckus FlexMaster Vulnerable Additional details in PDF/Text (Sign-in Required) source
Ruckus SmartZone 100 (SZ-100) 5.1 to 6.0 Vulnerable Additional details in PDF/Text (Sign-in Required) source
Ruckus SmartZone 144 (SZ-144) 5.1 to 6.0 Vulnerable Additional details in PDF/Text (Sign-in Required) source
Ruckus SmartZone 300 (SZ-300) 5.1 to 6.0 Vulnerable Additional details in PDF/Text (Sign-in Required) source
Ruckus Unleashed Vulnerable Additional details in PDF/Text (Sign-in Required) source
Ruckus Virtual SmartZone (vSZ) 5.1 to 6.0 Vulnerable Additional details in PDF/Text (Sign-in Required) source
RunDeck by PagerDuty All RunDeck Docs Link
RuneCast Analyzer 6.0.4 Not vuln Fix Fix Fix source