Skip to content

Latest commit

 

History

History
208 lines (205 loc) · 43.9 KB

File metadata and controls

208 lines (205 loc) · 43.9 KB

List of software (un)affected by the log4shell CVEs

About this list

0-9 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

R

Supplier Product Version (see Status) Status CVE-2021-4104 Status CVE-2021-44228 Status CVE-2021-45046 Status CVE-2021-45105 Notes Links
R All 4.1.1 Not vuln Not vuln Not vuln Not vuln source
R2ediviewer All R2ediviewer Link
Radware All Radware Support Link
Rapid7 AlcidekArt, kAdvisor, and kAudit on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 AppSpider Enterprise on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 AppSpider Pro on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 Insight Agent on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 InsightAppSec Scan Engine on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 InsightCloudSec/DivvyCloud on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 InsightConnect Orchestrator on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 InsightIDR Network Sensor on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 InsightIDR/InsightOps Collector & Event Sources on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 InsightOps DataHub 2.0.1 Fix source Fix
Rapid7 InsightOps non-Java logging libraries on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 InsightOps r77insight_java Logging Libary 3.0.9 Fix source
Rapid7 InsightOps r7insight_java logging library <=3.0.8 Not vuln Fix "Upgrade r7insight_java to 3.0.9" Rapid7 Statement
Rapid7 InsightVM Kubernetes Monitor on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 InsightVM/Nexpose on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 InsightVM/Nexpose Console on-prem Not vuln Not vuln Not vuln Not vuln Installations of the InsightVM/Nexpose have “log4j-over-slf4j-1.7.7.jar” packaged in them. This is a different library than log4j-core and is not vulnerable to Log4Shell. Rapid7 Statement
Rapid7 InsightVM/Nexpose Engine on-prem Not vuln Not vuln Not vuln Not vuln Installations of the InsightVM/Nexpose have “log4j-over-slf4j-1.7.7.jar” packaged in them. This is a different library than log4j-core and is not vulnerable to Log4Shell. Rapid7 Statement
Rapid7 IntSights virtual appliance on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 Logentries DataHub 1.2.0.822 Fix source Windows Fix Linux Fix
Rapid7 Logentries le_java Logging Libary All Vulnerable Migrate to v3.0.9 of r7insight_java source
Rapid7 Logentries le_java logging library All versions: this is a deprecated component Not vuln Fix "Migrate to version 3.0.9 of r7insight_java" Rapid7 Statement
Rapid7 Metasploit Framework on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 Metasploit Pro on-prem Not vuln Not vuln Not vuln Not vuln Metasploit Pro ships with log4j but has specific configurations applied to it that mitigate Log4Shell. A future update will contain a fully patched version of log4j. Rapid7 Statement
Rapid7 tCell Java Agent on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Rapid7 Velociraptor on-prem Not vuln Not vuln Not vuln Not vuln Rapid7 Statement
Raritan All Raritan Support Link
Ravelin All Ravelin Link
Real-Time Innovations (RTI) Distributed Logger Not vuln Not vuln Not vuln Not vuln RTI Statement
Real-Time Innovations (RTI) Recording Console Not vuln Not vuln Not vuln Not vuln RTI Statement
Real-Time Innovations (RTI) RTI Administration Console Not vuln Not vuln Not vuln Not vuln RTI Statement
Real-Time Innovations (RTI) RTI Code Generator Not vuln Not vuln Not vuln Not vuln RTI Statement
Real-Time Innovations (RTI) RTI Code Generator Server Not vuln Not vuln Not vuln Not vuln RTI Statement
Real-Time Innovations (RTI) RTI Micro Application Generator (MAG) as part of RTI Connext Micro 3.0.0, 3.0.1, 3.0.2, 3.0.3 Vulnerable RTI Statement
Real-Time Innovations (RTI) RTI Micro Application Generator (MAG) as part of RTI Connext Professional 6.0.0 and 6.0.1 Vulnerable RTI Statement
Real-Time Innovations (RTI) RTI Monitor Not vuln Not vuln Not vuln Not vuln RTI Statement
Red Hat A-MQ Clients 2 Not vuln source
Red Hat build of Quarkus Not vuln source
Red Hat CodeReady Studio 12.21.0 Not vuln Fix "CRS 12.21.1 Patch" CVE-2021-44228- Red Hat Customer Portal
Red Hat CodeReady Studio 12 Vulnerable source
Red Hat Data Grid 8 Not vuln Fix "RHSA-2021:5132" CVE-2021-44228- Red Hat Customer Portal
Red Hat Data Grid 8 8.2.2 Not vuln Fix "RHSA-2021:5132" source
Red Hat Decision Manager 7 Not vuln Not vuln Not vuln Not vuln CVE-2021-44228- Red Hat Customer Portal
Red Hat Descision Manager 7 Vulnerable source
Red Hat Enterprise Linux 6 Not vuln Not vuln Not vuln Not vuln CVE-2021-44228- Red Hat Customer Portal
Red Hat Enterprise Linux 7 Not vuln Not vuln Not vuln Not vuln CVE-2021-44228- Red Hat Customer Portal
Red Hat Enterprise Linux 8 Not vuln Not vuln Not vuln Not vuln CVE-2021-44228- Red Hat Customer Portal
Red Hat Integration Camel K Vulnerable source
Red Hat Integration Camel Quarkus Vulnerable source
Red Hat JBoss A-MQ Streaming 1.6.5 Not vuln Fix "RHSA-2021:5133" source
Red Hat JBoss Enterprise Application Platform 7 Not vuln Fix "Maven Patch - Affects only the Mavenized distribution. Container, Zip and RPM distro aren't affected." CVE-2021-44228- Red Hat Customer Portal
Red Hat JBoss Enterprise Application Platform 6 Not vuln source
Red Hat JBoss Enterprise Application Platform Expansion Pack Not vuln source
Red Hat JBoss Fuse 7 Not vuln Fix "RHSA-2021:5134" CVE-2021-44228- Red Hat Customer Portal
Red Hat JBoss Fuse 7 7.10.0 Not vuln Fix "RHSA-2021:5134" source
Red Hat log4j-core Not vuln Not vuln Not vuln Not vuln CVE-2021-44228- Red Hat Customer Portal
Red Hat OpenShift Application Runtimes 1.0 n.a. (see notes) Not vuln Fix "RHSA-2021:5093 - Red Hat build of Eclipse Vert.x 4.1.5 SP1" source
Red Hat OpenShift Container Platform 3.11 openshift3/ose-logging-elasticsearch5 3.11.z Not vuln Fix "RHSA-2021:5094" source
Red Hat OpenShift Container Platform 4 openshift4/ose-logging-elasticsearch6 4.6.z Not vuln Fix "RHSA-2021:5106" source
Red Hat OpenShift Container Platform 4 openshift4/ose-metering-hive 4.8.z Not vuln Fix "RHSA-2021:5108" source
Red Hat OpenShift Container Platform 4.6 openshift4/ose-metering-presto 4.6.52 Not vuln Fix "RHSA-2021:5141" source
Red Hat OpenShift Container Platform 4.7 openshift4/ose-metering-presto 4.7.40 Not vuln Fix "RHSA-2021:5107" source
Red Hat OpenShift Container Platform 4.8 openshift4/ose-metering-presto 4.8.24 Not vuln Fix "RHSA-2021:5148" source
Red Hat OpenShift Logging 5.0 openshift-logging/elasticsearch6-rhel8 5.0.10 Not vuln Fix "RHSA-2021:5137" source
Red Hat OpenShift Logging 5.0 openshift-logging/elasticsearch6-rhel8 5.3.1 Not vuln Fix "RHSA-2021:5129" source
Red Hat OpenShift Logging 5.1 openshift-logging/elasticsearch6-rhel8 5.1.5 Not vuln Fix "RHSA-2021:5128" source
Red Hat OpenShift Logging 5.2 openshift-logging/elasticsearch6-rhel8 5.2.4 Not vuln Fix "RHSA-2021:5127" source
Red Hat OpenStack Platform 13 (Queens) opendaylight Vulnerable source
Red Hat Process Automation 7 Not vuln Fix "Maven Patch - Affects only the Mavenized distribution. Container, Zip and RPM distro aren't affected." CVE-2021-44228- Red Hat Customer Portal
Red Hat Process Automation 7 Vulnerable source
Red Hat Satellite 5 Not vuln Not vuln Not vuln Not vuln CVE-2021-44228- Red Hat Customer Portal
Red Hat Single Sign-On 7 Not vuln Not vuln Not vuln Not vuln CVE-2021-44228- Red Hat Customer Portal
Red Hat Single Sign-On 7 Not vuln source
Red Hat Spacewalk Not vuln Not vuln Not vuln Not vuln CVE-2021-44228- Red Hat Customer Portal
Red Hat Vert.X 4 Not vuln Fix "RHSA-2021:5093" CVE-2021-44228- Red Hat Customer Portal
Red Hat Virtualization 4 Not vuln source
Red Hat OpenShift Container Platform 3.11 openshift3/ose-logging-elasticsearch5 Not vuln Fix "RHSA-2021:5094" CVE-2021-44228- Red Hat Customer Portal
Red Hat OpenShift Container Platform 4 openshift4/ose-logging-elasticsearch6 Not vuln Fix Please refer to Red Hat Customer Portal to find the left errata for your version. CVE-2021-44228- Red Hat Customer Portal
Red Hat OpenShift Container Platform 4 openshift4/ose-metering-hive Not vuln Fix Please refer to Red Hat Customer Portal to find the left errata for your version. CVE-2021-44228- Red Hat Customer Portal
Red Hat OpenShift Container Platform 4 openshift4/ose-metering-presto Not vuln Fix Please refer to Red Hat Customer Portal to find the left errata for your version. CVE-2021-44228- Red Hat Customer Portal
Red Hat OpenShift Logging logging-elasticsearch6-container Not vuln Fix Please refer to Red Hat Customer Portal to find the left errata for your version. CVE-2021-44228- Red Hat Customer Portal
Red Hat OpenStack Platform 13 (Queens) opendaylight Vulnerable End of Life CVE-2021-44228- Red Hat Customer Portal
Red Hat Software Collections rh-java-common-log4j Not vuln Not vuln Not vuln Not vuln CVE-2021-44228- Red Hat Customer Portal
Red Hat Software Collections rh-maven35-log4j12 Not vuln Not vuln Not vuln Not vuln CVE-2021-44228- Red Hat Customer Portal
Red Hat Software Collections rh-maven36-log4j12 Not vuln Not vuln Not vuln Not vuln CVE-2021-44228- Red Hat Customer Portal
Red5Pro All Red5Pro Link
Redgate Flyway All Not vuln Only vulnerable when using non-default config. source
Redis Enterprise & Open Source All Not vuln Redis Enterprise and Open Source Redis (self-managed software product) does not use Java and is therefore not impacted by this vulnerability source
Redis Jedis 3.7.1, 4.0.0-rc2 Not vuln Fix Jedis uses the affected library in test suites only. source
Reiner SCT All "Reiner SCT Forum"
ReportURI All ReportURI Link
ResMed AirView Not vuln source
ResMed myAir Not vuln source
Respondus All This advisory is available to customers only and has not been reviewed by CISA Respondus Support Link
Revenera FlexNet Publisher 64-bit License Server Manager Vulnerable Vulnerable source
Revenera / Flexera All Revenera / Flexera Community Link
Ricoh Commercial & Industrial Printing - Garment Printers Not vuln source
Ricoh Commercial & Industrial Printing - Production Printers Investigation source
Ricoh Office Products - Digital Duplicators Not vuln source
Ricoh Office Products - FAX Not vuln source
Ricoh Office Products - Interactive Whiteboards Not vuln source
Ricoh Office Products - Multifunction Printers/Copiers - Black & White MFP Not vuln source
Ricoh Office Products - Multifunction Printers/Copiers - Color MFP Not vuln source
Ricoh Office Products - Multifunction Printers/Copiers - Wide Format MFP Not vuln source
Ricoh Office Products - Printers - Black & White Laser Printers Not vuln source
Ricoh Office Products - Printers - Color Laser Printers Not vuln source
Ricoh Office Products - Printers - Gel Jet Printers Not vuln source
Ricoh Office Products - Printers - Handy Printers Not vuln source
Ricoh Office Products - Printers - Printer based MFP Not vuln source
Ricoh Office Products - Projectors Not vuln source
Ricoh Office Products - Video Conferencing Not vuln source
Ricoh Software & Solutions - @Remote Connector NX Not vuln source
Ricoh Software & Solutions - Card Authentication Package Series Not vuln source
Ricoh Software & Solutions - Certificate Enrolment Service Not vuln source
Ricoh Software & Solutions - Device Manager NX Accounting Not vuln source
Ricoh Software & Solutions - Device Manager NX Enterprise Not vuln source
Ricoh Software & Solutions - Device Manager NX Lite Not vuln source
Ricoh Software & Solutions - Device Manager NX Pro Not vuln source
Ricoh Software & Solutions - Docuware Not vuln source
Ricoh Software & Solutions - Enhanced Locked Print Series Not vuln source
Ricoh Software & Solutions - GlobalScan NX Not vuln source
Ricoh Software & Solutions - Intelligent Barcode Solution Not vuln source
Ricoh Software & Solutions - myPrint Not vuln source
Ricoh Software & Solutions - Printer Driver Packager NX Not vuln source
Ricoh Software & Solutions - Ricoh Print Management Cloud Not vuln source
Ricoh Software & Solutions - Ricoh Smart Integration (RSI) applications Not vuln source
Ricoh Software & Solutions - Ricoh Smart Integration (RSI) Platform and its applications Not vuln source
Ricoh Software & Solutions - Ricoh Streamline NX V2 Not vuln source
Ricoh Software & Solutions - Ricoh Streamline NX V3 Not vuln source
Ricoh Software & Solutions - Scan Workflow Navigator Not vuln source
Ricoh Software & Solutions - Streamline NX Share Not vuln source
RingCentral All RingCentral Security Bulletin
Riverbed AppResponse11 Not vuln "source"
Riverbed Aternity Investigation See source for latest updates source
Riverbed Client Accelerator Controllers and Client Accelerator (aka SteelCentral Controller for SteelHead Mobile and SteelHead Mobile) Not vuln "source"
Riverbed Flow Gateway Not vuln Not vuln Not vuln Not vuln "source"
Riverbed FlowTraq Not vuln Not vuln Not vuln Not vuln "source"
Riverbed Modeler Investigation "source"
Riverbed NetAuditor Desktop Investigation "source"
Riverbed NetAuditor Web Not vuln Not vuln Not vuln Not vuln "source"
Riverbed NetCollector Investigation "source"
Riverbed NetExpress Investigation "source"
Riverbed NetIM 1.x Not vuln Not vuln Not vuln Not vuln "source"
Riverbed NetIM 2.x Vulnerable Patches planned "source"
Riverbed NetIM Test Engine Not vuln Not vuln Not vuln Not vuln "source"
Riverbed NetPlanner Not vuln Not vuln Not vuln Not vuln "source"
Riverbed NetProfiler Not vuln Not vuln Not vuln Not vuln "source"
Riverbed Packet Analyzer Not vuln "source"
Riverbed Packet Trace Warehouse Not vuln "source"
Riverbed Portal 1.x Vulnerable Includes Log4j 2.2 "source"
Riverbed Portal 3.x Vulnerable Includes Log4j 2.13 "source"
Riverbed SaaS Accelerator Not vuln "source"
Riverbed Scon CX Not vuln Not vuln Not vuln Not vuln "source"
Riverbed Scon EX Analytics Vulnerable Patches planned "source"
Riverbed Scon EX Director Vulnerable Patches planned "source"
Riverbed Scon EX FlexVNF Not vuln Not vuln Not vuln Not vuln "source"
Riverbed SteelCentral Controller for SteelHead Not vuln "source"
Riverbed SteelFusion Edge Not vuln Not vuln Not vuln Not vuln "source"
Riverbed SteelFusionCore (appliance, virtual) Not vuln Not vuln Not vuln Not vuln "source"
Riverbed SteelHead CX (appliance, virtual, cloud) Not vuln "source"
Riverbed SteelHead Interceptor Not vuln "source"
Riverbed Transaction Analyzer Investigation "source"
Riverbed Transaction Analyzer Agents Not vuln Not vuln Not vuln Not vuln Log4j not in use "source"
Riverbed UCExpert Vulnerable "source"
Riverbed WinSec Controller for SteelHead (WSC) Not vuln "source"
RocketChat All All Not vuln source
Rockwell Automation FactoryTalk Analytics DataFlowML 4.00.00 Vulnerable Patch under development source
Rockwell Automation FactoryTalk Analytics DataView 3.03.00 Vulnerable Patch under development source
Rockwell Automation Industrial Data Center Gen 1, Gen 2, Gen 3, Gen 3.5 Not vuln Workaround Follow the mitigation instructions outlined by VMware in VMSA-2021-0028 source
Rockwell Automation MES EIG 3.03.00 Vulnerable Product discontinued. Customers should upgrade to EIG Hub if possible or work with their local representatives about alternative solutions. source
Rockwell Automation VersaVirtual Series A Not vuln Workaround Follow the mitigation instructions outlined by VMware in VMSA-2021-0028 source
Rockwell Automation Warehouse Management 4.01.00, 4.02.00, 4.02.01, 4.02.02 Vulnerable Patch under development source
Rollbar All Rollbar Blog Post
Rosette.com All Rosette.com Support Link
RSA NetWitness Orchestrator >= 6.0 Not vuln Workaround Mitigation for the ThreatConnect Application server is available, no impact described source
RSA NetWitness Platform 11.4 Not vuln Workaround It is theoretically possible to exploit the vulnerability to gain shell access to the NetWitness Platform source
RSA NetWitness Platform >= 11.5 Not vuln Workaround It is possible to leak system configuration data source
RSA SecurID Authentication Manager Not vuln Version 8.6 Patch 1 contains a version of log4j that is vulnerable, but this vulnerability is not exploitable. source
RSA SecurID Authentication Manager Prime Not vuln source
RSA SecurID Authentication Manager WebTier Not vuln source
RSA SecurID Governance and Lifecycle Not vuln Not vuln Not vuln Not vuln
RSA SecurID Governance and Lifecycle (SecurID G&L) Not vuln source
RSA SecurID Governance and Lifecycle Cloud Not vuln Not vuln Not vuln Not vuln
RSA SecurID Governance and Lifecycle Cloud (SecurID G&L Cloud) Not vuln source
RSA SecurID Identity Router Not vuln Not vuln Not vuln Not vuln
RSA SecurID Identity Router (On-Prem component of Cloud Authentication Service) Not vuln source
RSA Netwitness All RSA Netwitness Community Link
Rstudioapi All 0.13 Not vuln Not vuln Not vuln Not vuln source
Rubrik All This advisory is available to customers only and has not been reviewed by CISA Rubrik Support Link
Ruckus FlexMaster Vulnerable "Additional details in PDF/Text (Sign-in Required)" source
Ruckus SmartZone 100 (SZ-100) 5.1 to 6.0 Vulnerable "Additional details in PDF/Text (Sign-in Required)" source
Ruckus SmartZone 144 (SZ-144) 5.1 to 6.0 Vulnerable "Additional details in PDF/Text (Sign-in Required)" source
Ruckus SmartZone 300 (SZ-300) 5.1 to 6.0 Vulnerable "Additional details in PDF/Text (Sign-in Required)" source
Ruckus Unleashed Vulnerable "Additional details in PDF/Text (Sign-in Required)" source
Ruckus Virtual SmartZone (vSZ) 5.1 to 6.0 Vulnerable "Additional details in PDF/Text (Sign-in Required)" source
RunDeck by PagerDuty All RunDeck Docs Link
RuneCast Analyzer 6.0.4 Not vuln Fix Fix Fix source