Lucene search

K
kasperskyKaspersky LabKLA12390
HistoryDec 10, 2021 - 12:00 a.m.

KLA12390 RCE vulnerability in Apache Log4j

2021-12-1000:00:00
Kaspersky Lab
threats.kaspersky.com
1137

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

0.975 High

EPSS

Percentile

100.0%

Remote code execution vulnerability was found in Apache Log4j. Malicious users can exploit this vulnerability to execute arbitrary code.

Original advisories

Apache Log4j Security Vulnerabilities

Exploitation

Public exploits exist for this vulnerability.

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Related products

Apache-Log4j

CVE list

CVE-2021-44228 critical

Solution

Update to the latest version

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

Affected Products

  • Apache Log4j 2.0-beta9 before 2.15.03M Health Information Systems CGS7Signal SapphireABB Remote ServiceAPC by Schneider Electric Powerchute Business EditionAPC by Schneider Electric Powerchute Network ShutdownAPI Portal for VMware TanzuAbbott GLP Track SystemAccellion KiteworksAccruent AnalyticsAccruent BigCenterAccruent EvocoAccruent ExpesiteAccruent Famis 360Accruent LucernexAccruent MeridianAccruent SiteFM3Accruent SiteFM4Accruent SiterraAccruent VxMaintain/VxObserve/VxSustainAcronis See linkAdobe Automated Forms Conversion ServiceAdobe ColdFusionAdobe Experience Manager 6.4 Forms DesignerAdobe Experience Manager 6.5 Forms DesignerAkamai Siem Integration ConnectorAlertus ConsoleAlphatron Custo diagnosticsAmazon AMSAmazon API GatewayAmazon AWS API GatewayAmazon AWS AWS Certificate ManagerAmazon AWS AWS Service CatalogAmazon AWS AppFlowAmazon AWS AppSyncAmazon AWS CloudHSMAmazon AWS CodeBuildAmazon AWS CodePipelineAmazon AWS ConnectAmazon AWS Directory ServiceAmazon AWS DynamoDBAmazon AWS EKS, ECS, FargateAmazon AWS ELBAmazon AWS ElastiCacheAmazon AWS GlueAmazon AWS GreengrassAmazon AWS InspectorAmazon AWS IoT SiteWise EdgeAmazon AWS KMSAmazon AWS Kinesis Data StreamAmazon AWS LambdaAmazon AWS PollyAmazon AWS QuickSightAmazon AWS RDSAmazon AWS S3Amazon AWS SNSAmazon AWS SQSAmazon AWS Secrets ManagerAmazon AWS Systems ManagerAmazon AWS TextractAmazon AthenaAmazon ChimeAmazon Cloud DirectoryAmazon CloudFrontAmazon CloudWatchAmazon CognitoAmazon ConnectAmazon DocumentDBAmazon DynamoDBAmazon EC2Amazon ECR PublicAmazon EMRAmazon ElastiCacheAmazon Elastic Load BalancingAmazon EventBridgeAmazon Fraud DetectorAmazon InspectorAmazon Kafka (MSK)Amazon KendraAmazon Keyspaces (for Apache Cassandra)Amazon KinesisAmazon Lake FormationAmazon LexAmazon Linux 2 (AL2)Amazon Lookout for EquipmentAmazon MQAmazon MacieAmazon Managed Workflows for Apache Airflow (MWAA)Amazon MemoryDB for RedisAmazon MonitronAmazon NICEAmazon NeptuneAmazon OpenSearchAmazon PinpointAmazon RDSAmazon RedshiftAmazon RekognitionAmazon Route53Amazon S3Amazon SageMakerAmazon Simple Notification Service (SNS)Amazon Simple Queue Service (SQS)Amazon Simple Workflow Service (SWF)Amazon Single Sign-OnAmazon Step FunctionsAmazon TimestreamAmazon VPCAmazon WorkSpaces/AppStream 2.0Apache ArchivaApache Camel JBangApache Camel KarafApache DruidApache DubboApache FlinkApache FortressApache GeodeApache HBaseApache HadoopApache HiveApache JMeterApache JSPWikiApache JamesApache JenaApache KafkaApache KarafApache NiFiApache OFBizApache OzoneApache SOLRApache SkyWalkingApache StrutsApache TapestryApache TikaApache TrafficControlApereo CASApereo OpencastAppDynamics with Cisco Secure ApplicationAppeon PowerBuilderAppian PlatformAptibleArcserve See linkArduino IDEArista Networks Analytics Node for Converged Cloud Fabric (formerly Big Cloud Fabric)Arista Networks Analytics Node for DANZ Monitoring Fabric (formerly Big Monitoring Fabric)Arista Networks CloudVision PortalArista Networks CloudVision Wi-Fi, virtual appliance or physical applianceArista Networks Embedded Analytics for Converged Cloud Fabric (formerly Big Cloud Fabric)Atlassian Bamboo Server & Data CenterAtlassian Bitbucket Server & Data CenterAtlassian Confluence Server & Data CenterAtlassian Confluence-CIS CSAT ProAtlassian Confluence-CIS-CAT LiteAtlassian Confluence-CIS-CAT Pro Assessor v3 Full and DissolvableAtlassian Confluence-CIS-CAT Pro Assessor v4Atlassian Crowd Server & Data CenterAtlassian CrucibleAtlassian FisheyeAtlassian Jira Server & Data CenterAtos Unify First Response OpenScape Policy StoreAtos Unify OpenScape Contact CenterAtos Unify OpenScape Contact Media ServiceAtos Unify OpenScape Enterprise ExpressAtos Unify OpenScape UCAtos Unify OpenScape VoiceAutomation Anywhere Automation 360 CloudAvaya AnalyticsAvaya Aura for OneCloud PrivateAvaya Aura Application Enablement ServicesAvaya Aura Contact CenterAvaya Aura Device ServicesAvaya Aura Media ServerAvaya Aura Presence ServicesAvaya Aura Session ManagerAvaya Aura System ManagerAvaya Aura Web GatewayAvaya Breeze™Avaya Business Rules EngineAvaya CRM Connector - Connected DesktopAvaya Callback AssistAvaya Contact Center SelectAvaya Control ManagerAvaya Device Enablement ServiceAvaya Device Enrollment ServiceAvaya Equinox™ ConferencingAvaya IP Office™ PlatformAvaya Interaction CenterAvaya MeetingsAvaya OneCloud-PrivateAvaya Proactive Outreach ManagerAvaya Session Border Controller for EnterpriseAvaya Social Media HubAvaya Workforce EngagementAvaya one cloud private -UCaaS - Mid Market AuraBCT LIBERBCT e-InvoiceBMC AMI Ops InsightBMC Bladelogic Database AutomationBMC Helix Data ManagerBMC Helix ITSMBMC Helix PlatformBMC Remedy Smart ReportingBMC TrueSight Automation ConsoleBackblaze CloudBarco OpSpaceBeckman Coulter Information SystemsBeyondTrust Privilege Management Reporting in BeyondInsightBioJava Java library for processing biological dataBosch Rexroth Bosch IoT gatewayBosch Security Systems PRAESENSA PRA-APASBrian Pangburn SwingSetBroadcom CA Risk AuthenticationBroadcom CA Strong AuthenticationBroadcom Cloud Workload Assurance (CWA)Broadcom Cloud Workload Protection (CWP)Broadcom Cloud Workload Protection for Storage (CWP:S)Broadcom Email Security Service (ESS)Broadcom LiveUpdate Administrator (LUA)Broadcom Secure Access Cloud (SAC)Broadcom Symantec Advanced AuthenticationBroadcom Symantec Endpoint Detection and Response (EDR)Broadcom Symantec Endpoint Protection Manager (SEPM)Broadcom Symantec Endpoint Security (SES)Broadcom Symantec Privileged Access Manager (PAM)Broadcom VIP Authentication HubBroadcom Web Isolation (WI) CloudBroadcom Web Security Service (WSS) ReportingBrocade AMPOS V2.x and V3.xBrocade EZSwitchBrocade Fabric OSBrocade Network AdvisorBrocade SANnavCIS CAT LiteCIS CAT Pro Assessor v3 Full and DissolvableCIS CAT Pro Assessor v4CIS CSAT ProCanon RialtoCanon Solution Health (On-Prem)Canon VL Alphenix Angio Workstation (AWS)Canon Vitrea AdvancedCanon Vitrea ConnectionCaseWare CloudCisco AppDynamicsCisco Application Policy Infrastructure Controller (APIC) - Network Insights Base AppCisco Automated Subsea TuningCisco BroadWorksCisco Business Process AutomationCisco CX CloudCisco Call StudioCisco Cloud ConnectCisco CloudCenterCisco CloudlockCisco Common Services Platform Collector (CSPC)Cisco Computer Telephony Integration Object Server (CTIOS)Cisco Connected Mobile Experiences (CMX)Cisco Contact Center Domain Manager (CCDM)Cisco Contact Center Management Portal (CCMP)Cisco Crosswork Data GatewayCisco Crosswork Network ControllerCisco Crosswork Optimization EngineCisco Crosswork Platform InfrastructureCisco Crosswork Situation ManagerCisco Crosswork Zero Touch Provisioning (ZTP)Cisco Cyber Vision Sensor Management ExtensionCisco DNA CenterCisco DNA SpacesCisco Data Center Network Manager (DCNM)Cisco DuoCisco Emergency ResponderCisco Enterprise Chat and EmailCisco Evolved Programmable Network ManagerCisco FinesseCisco Firepower Threat Defense (FTD) managed by FDMCisco HyperFlex SystemCisco Hyperflex Storage Replication AdapterCisco IOx Fog DirectorCisco Identity Services Engine (ISE)Cisco Integrated Management Controller (IMC) SupervisorCisco Intersight Virtual ApplianceCisco MDS 9000 Series Multilayer SwitchesCisco Network Assurance EngineCisco Network Services Orchestrator (NSO)Cisco Nexus Dashboard (formerly Cisco Application Services Engine)Cisco Nexus InsightsCisco Nexus switchesCisco Packaged Contact Center EnterpriseCisco SD-WAN vManageCisco UCS C-Series Rack Servers – Integrated Management ControllerCisco UCS Central SoftwareCisco UCS DirectorCisco UCS ManagerCisco Unified Communications Manager CloudCisco Unified Communications Manager IM & Presence Service (formerly CUPS)Cisco Unified Contact Center EnterpriseCisco Unified Contact Center ExpressCisco Unified Intelligent Contact Management EnterpriseCisco Unified SIP Proxy SoftwareCisco Unity ConnectionCisco Video Surveillance Operations ManagerCisco Virtualized Infrastructure ManagerCisco WAN Automation Engine (WAE)Cisco Webex Cloud-Connected UC (CCUC)Cisco Webex Meetings ServerCisco Workload Optimization ManagerCisco eSIM FlexCitrix Endpoint Management ( XenMobile Server)Citrix Endpoint Management (XenMobile Server)Citrix Virtual Apps and Desktops (XenApp & XenDesktop)Clavister EasyAccessClavister InCenterCloud Mobility for Dell EMC StorageCloudera AmbariCloudera Arcadia EnterpriseCloudera CDH, HDP, and HDFCloudera CDP Private Cloud BaseCloudera CDS 3 Powered by Apache SparkCloudera CDS 3.2 for GPUsCloudera Cybersecurity PlatformCloudera Data Engineering (CDE)Cloudera Data Flow (CFM)Cloudera Data Science Workbench (CDSW)Cloudera Data Steward Studio (DSS)Cloudera Data Visualization (CDV)Cloudera Data Warehouse (CDW)Cloudera DataFlow (CDF)Cloudera Edge Management (CEM)Cloudera EnterpriseCloudera Flow Management (CFM)Cloudera Hortonworks Data Platform (HDP)Cloudera Machine Learning (CML)Cloudera Management ConsoleCloudera Manager (Including Backup Disaster Recovery (BDR) and Replication Manager)Cloudera Replication ManagerCloudera Runtime (including Data Hub and all Data Hub templates)Cloudera Stream Processing (CSP)Cloudera Streaming Analytics (CSA)Cloudera Workload XMCloudogu EcosystemCode42 AppCode42 CrashplanCohesity SoftwareCommvaultComputer Vision Annotation Tool maintained by IntelConfluent CloudConfluent ConnectorsConfluent ElasticSearch Sink ConnectorConfluent Google DataProc Sink ConnectorConfluent HDFS 2 Sink ConnectorConfluent HDFS 3 Sink ConnectorConfluent PlatformConfluent Splunk Sink ConnectorConfluent VMWare Tanzu GemFire Sink ConnectorConfluent for KubernetesConnect2id serverConnectwise PerchContinuous Delivery for Puppet EnterpriseContrast Hosted SaaS EnviromentsContrast On-premises (EOP) EnvironmentsContrast ScanControlUpCoralogixCouchbase ElasticSearch connectorCyberark Identity - Secure Web Sessions (SWS)Cyberark Privilege Cloud - Service (SaaS)Cyberark Remote Access (Alero) - ConnectorCyberark Remote Access (Alero) - Service (SaaS)DDN at Scale productsDatadog AgentDatadogHQ datadog-kafka-connect-logsDatadogHQ datadog-lambda-javaDatev DATEV Mittelstand Faktura and DATEV Mittelstand Faktura mit Rechnungswesen compactDatev DATEV Wages and Salaries compactDatev DATEV-SmartITDatev DATEVaspDatev Jasper ReportsDatev Lawyer’s mailboxDebian Apache-log4j2Decos JOIN Zaak & Document (Private Cloud)Dell APEX ConsoleDell APEX Data Storage ServicesDell Cloud IQDell Connectrix (Cisco MDS DCNM)Dell EMC APEX ConsoleDell EMC APEX Data Storage ServicesDell EMC AppSyncDell EMC AtmosDell EMC AvamarDell EMC BSN Controller NodeDell EMC CenteraDell EMC Chassis Management Controller (CMC)Dell EMC Cloud Disaster RecoveryDell EMC CloudLinkDell EMC CloudboostDell EMC Compellent – Dell Storage Manager ClientDell EMC Connectrix (Brocade)Dell EMC Connectrix (Cisco MDS 9000 switches)Dell EMC Connectrix (Cisco MDS DCNM)Dell EMC Connectrix B-Series SANnavDell EMC Container Storage ModulesDell EMC Data Computing Appliance (DCA)Dell EMC Data Domain OSDell EMC Data Protection AdvisorDell EMC Data Protection CentralDell EMC Data Protection SearchDell EMC DataIQDell EMC Dell Hybrid Client (DHC)Dell EMC Dell ImageAssistDell EMC Dell Networking X-SeriesDell EMC Dell Open Manage MobileDell EMC Dell Open Manage Server AdministratorDell EMC Dell Open Management Enterprise – ModularDell EMC Dell OpenManage Change ManagementDell EMC Dell OpenManage Enterprise Power Manager PluginDell EMC Dell Wyse Management Suite Import ToolDell EMC DellEMC OpenManage Enterprise ServicesDell EMC Disk Library for MainframeDell EMC ECSDell EMC Embedded NASDell EMC Enterprise Hybrid CloudDell EMC Enterprise Storage Analytics for vRealize OperationsDell EMC Equallogic PSDell EMC GeoDriveDell EMC ISG Drive & Storage MediaDell EMC Infinity MLK (firmware)Dell EMC Integrated Dell Remote Access Controller (iDRAC)Dell EMC Integrated System for Azure Stack HCIDell EMC Integrated System for Microsoft Azure Stack HubDell EMC Isilon InsightIQDell EMC IsilonSD Management ServerDell EMC License ManagerDell EMC Mainframe EnablersDell EMC Metro NodeDell EMC MyDell MobileDell EMC NetWorkerDell EMC Networking BIOSDell EMC Networking N-SeriesDell EMC Networking OS9Dell EMC Networking OnieDell EMC Networking Virtual Edge Platform with VersaOSDell EMC OMIMSSC (OpenManage Integration for Microsoft System Center)Dell EMC OMNIADell EMC OpenManage Connections – NagiosDell EMC OpenManage Connections – ServiceNowDell EMC OpenManage EnterpriseDell EMC OpenManage Integration for Microsoft System Center for System Center Operations ManagerDell EMC OpenManage Integration for VMware vCenterDell EMC OpenManage Integration with Microsoft Windows Admin CenterDell EMC OpenManage Management pack for vRealize OperationsDell EMC OpenManage Network IntegrationDell EMC OpenManage Operations Connector for Micro Focus Operations Bridge ManagerDell EMC OpenManage integration for SplunkDell EMC PPDM SearchDell EMC PowerEdge BIOSDell EMC PowerEdge Operating SystemsDell EMC PowerFlex ApplianceDell EMC PowerFlex ManagerDell EMC PowerFlex RackDell EMC PowerFlex Software (SDS)Dell EMC PowerMax, VMAX, VMAX3 and VMAX AFADell EMC PowerPathDell EMC PowerProtect Cyber RecoveryDell EMC PowerProtect DP Series Appliance (iDPA)Dell EMC PowerProtect Data ManagerDell EMC PowerScale OneFSDell EMC PowerShell for PowerMaxDell EMC PowerShell for PowerstoreDell EMC PowerShell for UnityDell EMC PowerStoreDell EMC PowerSwitch Z9264F-ON BMC, Dell EMC PowerSwitch Z9432F-ON BMCDell EMC PowerVault ME4 Series Storage ArraysDell EMC RecoverPointDell EMC Remotely AnywhereDell EMC Repository Manager (DRM)Dell EMC Riptide (firmware)Dell EMC Ruckus SmartZone 300 ControllerDell EMC Ruckus Virtual SoftwareDell EMC SRM vAppDell EMC SRS Policy ManagerDell EMC SRS VEDell EMC Secure Connect Gateway (SCG) 5.0 ApplianceDell EMC Secure Connect Gateway (SCG) Policy ManagerDell EMC Server StorageDell EMC Smart Fabric Storage SoftwareDell EMC SmartFabric DirectorDell EMC Software RAIDDell EMC Solutions EnablerDell EMC SonicDell EMC SourceOneDell EMC Storage Center OS and additional SC applications unless otherwise notedDell EMC Storage Center – Dell Storage ManagerDell EMC Streaming Data PlatformDell EMC SupportAssist Client CommercialDell EMC SupportAssist Client ConsumerDell EMC SupportAssist EnterpriseDell EMC Systems Update (DSU)Dell EMC Unisphere 360Dell EMC Unisphere CentralDell EMC Unisphere for PowerMaxDell EMC Unisphere for VMAXDell EMC Unisphere for VNXDell EMC UnityDell EMC Update Manager PluginDell EMC VNX Control StationDell EMC VNX2Dell EMC VNXe3200Dell EMC VPLEXDell EMC VblockDell EMC ViPR ControllerDell EMC Virtual Storage IntegratorDell EMC Vsan Ready NodesDell EMC VxBlockDell EMC VxFlex Ready NodesDell EMC VxRailDell EMC Warnado MLK (firmware)Dell EMC XCDell EMC XtremIODell EMC iDRAC Service Module (iSM)Dell EMC vRealize Data Protection ExtensionDell Open Management Enterprise - ModularDell OpenManage EnterpriseDell Secure Connect Gateway (SCG) ApplianceDell Secure Connect Gateway (SCG) Policy ManagerDell SupportAssist EnterpriseDell Unisphere CentralDell VMware vRealize Automation 8.xDell VMware vRealize Orchestrator 8.xDell VblockDell VxBlockDell Wyse Management SuiteDell vRealize Data Protection Extension Data ManagementDell vRealize Data Protection Extension for vRealize Automation (vRA) 8.xDeltares Delft-FEWSDotCMS Hybrid Content Management SystemDynatrace ActiveGatesDynatrace Cloud ServicesDynatrace ExtensionsDynatrace FedRamp SAASDynatrace SAASDynatrace Synthetic Private ActiveGateDynatrace Synthetic public locationsEVL Labs JGAAPEaton Power ProtectorEaton UndisclosedEclecticIQ TIPElastic LogstashElastic searchEllucian Banner AnalyticsEllucian ColleagueEsri ArcGIS Data StoreEsri ArcGIS EnterpriseEsri ArcGIS GeoEvent ServerEsri ArcGIS ServerEsri ArcGIS Workflow Manager ServerEsri Portal for ArcGISEwon (HMS-Networks) eCatcherExtensis Universal Type ServerExtraHop Reveal(x)Extreme Networks IQVAF-Secure Elements ConnectorF-Secure Endpoint ProxyF-Secure Messaging Security GatewayF-Secure Policy ManagerFAST LTA Silent BrickFedEx Ship ManagerFiix CMMS CoreFiix CMMS coreFileCap ServerFortinet FortiAIOpsFortinet FortiAnalyzer Big DataFortinet FortiCASBFortinet FortiCWPFortinet FortiConverter PortalFortinet FortiEDR CloudFortinet FortiIsolatorFortinet FortiMonitorFortinet FortiNACFortinet FortiPolicyFortinet FortiPortalFortinet FortiSIEMFortinet FortiSOARFortinet ShieldXFujitsu ETERNUS AB/HBFujitsu ETERNUS CS800Fujitsu ETERNUS DX/AFFujitsu ETERNUS JXFujitsu ETERNUS LT20/40/60Fujitsu ETERNUS SFGE Gas Power Asset Performance Management (APM)GE Gas Power Baseline Security Center (BSC)GE Gas Power Control ServerGE Gas Power Tag Mapping ServiceGigamon Fabric ManagerGitHub Enterprise ServerGitHub Enterprise CloudGitLab Dependency ScanningGitLab Gemnasium-MavenGitLab PMD OSSGitLab SASTGitLab SpotbugsGoAnywhere GatewayGoAnywhere MFTGradle EnterpriseGraylog ForwarderGraylog ServerGuardedBoxHENIX Squash TMHP Teradici Cloud Access ControllerHP Teradici EMSDKHP Teradici Management ConsoleHP Teradici PCoIP Connection ManagerHPE 3PAR Service ProcessorHPE 3PAR StoreServ ArraysHPE 3PAR StoreServ Management and Core Software MediaHPE Aruba NetInsight Network AnalyticsHPE Authentication Server Function (AUSF)HPE B-series Fibre Channel SwitchHPE B-series SAN Extension SwitchHPE ClusterStor Data Services (CDS)HPE Cray EX System Monitoring Application (SMA)HPE Cray View for ClusterStorHPE Data Center Fabric Manager (DCNM) – C-Series DCNMHPE Data Management FrameworkHPE Device Entitlement Gateway (DEG)HPE DragonHPE Dynamic SIM Provisioning (DSP)HPE Edge Infrastructure AutomationHPE Ezmeral Container PlatformHPE Ezmeral Data FabricHPE Ezmeral Ecosystem Pack (EEP)HPE HP XP Command View Advanced Edition Software – HostDataCollector ComponentHPE Hyper Converged 250 SystemHPE Hyper Converged 250/380 SystemHPE Hyper Converged 380HPE Infosight for StorageHPE Integrated Home Subscriber Server Software SeriesHPE Intelligent AssuranceHPE Intelligent Management Center (IMC) Standard and EnterpriseHPE Intelligent Management Center (iMC)HPE MSAHPE Media Workflow Master (MWM)HPE Network Function Virtualization Director (NFV Director)HPE Nimble StorageHPE OneViewHPE Parallel File System StorageHPE Parallel Filesystem Storage (PFSS)HPE Primera StorageHPE RESTful Interface Tool (iLOREST)HPE Real Time Management System (RTMS)HPE Remote SIM Provisioning Manager (RSPM)HPE Revenue Intelligence Software SeriesHPE SANnav Management SoftwareHPE Service Director (SD)HPE Shasta Monitoring Framework (SMF)HPE SimpliVity 2600HPE SimpliVity 325HPE SimpliVity 380HPE SimpliVity OmniCubeHPE Smart Storage Administrator (SSA)HPE StoreEasyHPE StoreEver CVTLHPE StoreEver LTO Tape DrivesHPE StoreEver MSL Tape LibrariesHPE StoreOnceHPE StoreServ Management Console (SSMC)HPE StoreVirtualHPE Telecom Analytics Smart Profile Server (TASPS)HPE Telecom Management Information Platform Software SeriesHPE Trueview Inventory Software SeriesHPE Unified Data Management (UDM)HPE Universal IoT (UioT) PlatformHPE Unstructured Data Storage Function (UDSF)HPE User Data Repository (UDR)HPE Virtual ConnectHPE Virtual Headend Manager (vHM)HPE XP Advanced Edition (HDVM) -Agent ComponentHPE XP Advanced Edition (HDVM) -Server ComponentHPE XP Command ViewHPE XP Common ServicesHPE XP Configuration ManagerHPE XP Data Protection Manager (DPM)HPE XP Dynamic Link Manager (HDLM)HPE XP Global Link Manager (HGLM)HPE XP P9500HPE XP Performance Advisor SoftwareHPE XP Plugin – vCST (vCenter Storage Plugin), Redhat Ansible, Terraform, OLVMHPE XP Plugins – VASA, vROPs, SCOM, Veeam, Insight, HSPC, HRPC, HSPP, VSS, HDRE, Base Script, HBSDHPE XP Replication Manager (HRPM)HPE XP Tiered Storage Manager (HTSM)HPE XP Tuning Manager (HTNM)HPE XP7HPE XP8HPE Zerto productsHPE enhanced Internet Usage Manager (eIUM)Helpsystems Clearswift Secure Email GatewayHelpsystems Clearswift Secure Exchange GatewayHelpsystems Clearswift Secure ICAP GatewayHelpsystems Clearswift Secure Web GatewayHexagon ERDAS APOLLO - Catalog ExplorerHexagon Geoprocessing ServerHexagon HxGN OnCall Mobile AdminHexagon HxGN OnCall RecordsHexagon M.App EnterpriseHexagon M.App X - Geoprocessing ServerHexagon inPURSUIT Server (Workflow)Hitachi Energy AxisHitachi Energy FOXMAN-UNHitachi Energy Lumada APM On-premisesHitachi Energy Lumada APM SaaSHitachi Energy Network Manager Outage Management Interface (OMI) – Third Party Oracle Database Components (Trace File Analyzer, SQL Developer, Property Graph)Hitachi Energy Network Manager SCADA/EMS, Ranger and NMR Product – Third Party Oracle Database Components (Trace File Analyzer, SQL Developer, Property Graph)Hitachi Energy RelCareHitachi Energy UNEMHitachi Energy e-Mesh MonitorHitachi Energy nMarket Global I-SEMHitachi Vantara Business Continuity Manager (BCM)Hitachi Vantara CCI / RAID ManagerHitachi Vantara Content IntelligenceHitachi Vantara Content Platform (versions 8.2 and higher)Hitachi Vantara Content Platform AnywhereHitachi Vantara Content Platform GatewayHitachi Vantara Content Platform S Series (all models)Hitachi Vantara Export Tool 2 (Monitor 2)Hitachi Vantara HCP for Cloud ScaleHitachi Vantara HNAS 30x0 SeriesHitachi Vantara HNAS 4000 SeriesHitachi Vantara HNAS 5000 SeriesHitachi Vantara Hitachi (VASA) Provider for VMware vCenterHitachi Vantara Hitachi 520H/X Blade (all versions)Hitachi Vantara Hitachi 540A Blade (all versions)Hitachi Vantara Hitachi Adaptable Modular Storage DF800S, DF800M, DF800H (AMS 2x00)Hitachi Vantara Hitachi Adapters (Bundle) for Oracle DatabaseHitachi Vantara Hitachi Block Storage Driver (HBSD / OpenStack)Hitachi Vantara Hitachi Compute Blade CB500, CB2000, CB2500Hitachi Vantara Hitachi Compute Systems Manager (HCSM)Hitachi Vantara Hitachi Content Software for File (HCSF)Hitachi Vantara Hitachi Data IngestorHitachi Vantara Hitachi Device Manager (HDvM), HDVM Agent and HDVM Server are unaffected.Hitachi Vantara Hitachi Disaster Recovery Solution (HDRS)Hitachi Vantara Hitachi Dynamic Link Manager (HDLM)Hitachi Vantara Hitachi File Services Manager (HFSM)Hitachi Vantara Hitachi Global Link Manager (HGLM)Hitachi Vantara Hitachi Infrastructure Analytics Advisor (HIAA)Hitachi Vantara Hitachi Infrastructure Management Pack for VMware vRealize Operations (vROPS)Hitachi Vantara Hitachi Ops Center Administrator (HSA)Hitachi Vantara Hitachi Ops Center Automator (HAD)Hitachi Vantara Hitachi Ops Center – Analyzer Viewpoint / Server / RAID AgentHitachi Vantara Hitachi Ops Center – Analyzer, Analyzer ProbeHitachi Vantara Hitachi Ops Center – Common Services (HOC)Hitachi Vantara Hitachi Ops Center – Configuration Manager REST API (HCM)Hitachi Vantara Hitachi Ops Center – ProtectorHitachi Vantara Hitachi Remote OpsHitachi Vantara Hitachi Replication Manager (HRpM)Hitachi Vantara Hitachi Replication Plugin for Containers (HRPC)Hitachi Vantara Hitachi Storage Adapter for SAP HANA DBA CockpitHitachi Vantara Hitachi Storage Adapter for VMware Site Recovery Manager (VSP SRA)Hitachi Vantara Hitachi Storage Connector for VMware vRealize Orchestrator (vRO)Hitachi Vantara Hitachi Storage Content Pack for VMware vRealize Log Insight (vRLI)Hitachi Vantara Hitachi Storage Modules for Red Hat AnsibleHitachi Vantara Hitachi Storage Plugin for Containers (HSPC)Hitachi Vantara Hitachi Storage Plugin for Prometheus (HSPP)Hitachi Vantara Hitachi Storage Plugin for VMware vCenterHitachi Vantara Hitachi Storage Replication Adapter for VMware Site Recovery Manager (VSP SRA)Hitachi Vantara Hitachi Tiered Storage Manager (HTSM)Hitachi Vantara Hitachi Tuning Manager (HTnM)Hitachi Vantara Hitachi Unified Storage VM (HUS VM) HM700Hitachi Vantara Hitachi Virtual Storage Platform (VSP) RAID 700Hitachi Vantara Hitachi Virtual Storage Platform VSP 5200, VSP 5200H, VSP 5600, VSP 5600HHitachi Vantara Hitachi Virtual Storage Platform VSP E990, VSP E790, VSP E590Hitachi Vantara Hitachi Virtual Storage Platform VSP F/G350, VSP F/G370, VSP F/G700, VSP F/G900Hitachi Vantara Hitachi Virtual Storage Platform VSP G200, VSP F/G/N400, VSP F/G/N600, VSP F/G/N800Hitachi Vantara Infrastructure Adapter for Microsoft Windows PowershellHitachi Vantara Ops Center Protector Adapter for VMware Site Recovery Manager (Protector SRA)Hitachi Vantara Ops Center Protector Connector for VMware vRealize Orchestrator (Protector vRO)Hitachi Vantara SMUHitachi Vantara Storage Navigator Modular 2 (SNM2)Hitachi Vantara UCP AdvisorHitachi Vantara Veeam Plugin for VSP StorageHitachi Vantara Virtual Storage Platform Gx00/Fx00 NAS ModulesHitachi Vantara Virtual Storage Platform Nx00 NAS ModulesHitachi Vantara ashiCorp Terraform Provider for Hitachi StorageHostiFi Unifi hostingHuawei productsIBM A9000/RIBM Block StorageIBM Business Automation WorkflowIBM Cloud BackupIBM Cloud Object StorageIBM Cloud PrivateIBM Cognos AnalyticsIBM Content Delivery NetworkIBM Copy Services ManagerIBM Curam SPMIBM DB2 ServerIBM DS8000 Hardware Management ConsoleIBM Elastic Storage System (ESS)IBM File StorageIBM Flash System 900 (& 840)IBM FlashSystem 5000 SeriesIBM FlashSystem 7000 SeriesIBM FlashSystem 9000 SeriesIBM FlashSystem v9000IBM Hyper-Scale Manager (HSM)IBM MQIBM NetezzaIBM Power HMCIBM Power Hardware Management ConsoleIBM PowerVM HypervisorIBM PowerVM VIOSIBM SAN Volume Controller and Storwize FamilyIBM SPSS StatisticsIBM Security Access ManagerIBM Spectrum AccelerateIBM Spectrum Archive Library EditionIBM Spectrum ConductorIBM Spectrum ControlIBM Spectrum Copy Data ManagementIBM Spectrum DiscoverIBM Spectrum Protect Backup-Archive ClientIBM Spectrum Protect Client Management ServiceIBM Spectrum Protect Client Web User InterfaceIBM Spectrum Protect HSM for WindowsIBM Spectrum Protect Operations CenterIBM Spectrum Protect PlusIBM Spectrum Protect ServerIBM Spectrum Protect Snapshot for UNIXIBM Spectrum Protect Snapshot for VMwareIBM Spectrum Protect Snapshot for WindowsIBM Spectrum Protect for Databases: Data Protection for OracleIBM Spectrum Protect for Databases: Data Protection for SQLIBM Spectrum Protect for Enterprise Resource PlanningIBM Spectrum Protect for Mail: Data Protection for DominoIBM Spectrum Protect for Mail: Data Protection for ExchangeIBM Spectrum Protect for Space ManagementIBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-VIBM Spectrum Protect for Virtual Environments: Data Protection for VMwareIBM Spectrum Protect for WorkstationsIBM Spectrum Protect for z/OS USS Client and APIIBM Spectrum ScaleIBM Spectrum SymphonyIBM Spectrum VirtualizeIBM Sterling Fulfillment OptimizerIBM Sterling Inventory VisibilityIBM Storage TS2280IBM Storage TS2900 LibraryIBM Storage TS4500 LibraryIBM Storage Virtualization Engine TS7700IBM System Storage Storwize V7000 Unified (V7000U)IBM TS4300IBM Tape System Library ManagerIBM Tivoli Storage FlashCopy Manager for WindowsIBM Total Storage Service Console (TSSC) / TS4500 IMCIBM VM Manager Tool (part of License Metric Tool)IBM WebsphereIBM XIV Management ToolsIBM XIV Storage SystemINIT GmbH Mobile PlanImprivata PAMInfinidat Host PowerToolsInfinidat InfiniBox Active-Active WitnessInfinidat InfiniBox F-seriesInfinidat InfiniGuard B-seriesInfinidat InfiniMetricsInfinidat InfiniShellInfinidat InfiniVerseInfinidat SnapRotatorInfor Rich Desktop ClientInformatica Information Deployment ManagerInformatica Secure Agents (Cloud hosted)Intel Audio Development KitIntel Computer Vision Annotation ToolIntel Dataleft ManagerIntel Genomics Kernel LibraryIntel Secure Device OnboardIntel Sensor Solution Firmware Development KitIntel System DebuggerIntel System StudioIntel oneAPI sample browser plugin for EclipseInterSystems ISC ReportsInterSystems TrakCare CoreIntland codebeamerIvanti AvalacheJamf Nation Jamf CloudJamf Nation Jamf Pro (hosted on-prem)Jamf ProJava Melody earlier than 1.90.0JetBrains Code With MeJetBrains Floating license serverJetBrains HubJetBrains UpSourceJetBrains YouTrack InCloudJetBrains YouTrack StandaloneJitsi jitsi-videobridgeJohnson Controls OpenBlue BridgeJohnson Controls RFID Overhead360 BackendJuniper Networks Junos Space Network Management PlatformJuniper Networks Northstar ControllerJuniper Networks Paragon InsightsJuniper Networks Paragon PathfinderJuniper Networks Paragon PlannerKaltura Blackboard Learn SaaS in the classic Learn experienceKaltura Blackboard Learn Self- and Managed-HostingKeeperKofax Communication Manager (KCM)LOGalyze SIEM & log analyzer toolLastPass MFALeanIXLenovo CP-SB-D20 (ThinkAgile)Lenovo CP-SB-D20E (ThinkAgile)Lenovo CP6000 (ThinkAgile)Lenovo DSS-GLenovo NetApp ONTAP Tools for VMware vSphereLenovo P920 Rack WorkstationLenovo SR530 (ThinkSystem)Lenovo SR550 (ThinkSystem)Lenovo SR570 (ThinkSystem)Lenovo SR590 (ThinkSystem)Lenovo SR630 (ThinkSystem)Lenovo SR630 V2 (ThinkSystem)Lenovo SR645 (ThinkSystem)Lenovo SR650 (ThinkSystem)Lenovo SR650 V2 (ThinkSystem)Lenovo SR665 (ThinkSystem)Lenovo SR850 V2 (ThinkSystem)Lenovo SR860 V2 (ThinkSystem)Lenovo ST550 (ThinkSystem)Lenovo ST558 (ThinkSystem)Lenovo ThinkAgile HXLenovo ThinkAgile VXLenovo ThinkSystem StorageLenovo XClarity Administrator (LXCA)Lenovo XClarity Energy Manager (LXEM)Lenovo XClarity Integrator (LXCI) for Microsoft Azure AnalyticsLenovo XClarity Integrator (LXCI) for ServiceNowLenovo XClarity Integrator (LXCI) for VMware vCenterLenovo XClarity Orchestrator (LXCO)LiveAction LiveNALiveAction LiveNXLooker earlier than 21.20LucaNet 12 LTS earlier than 1911.0.192+3, 13 LTS earlier than 2011.0.112+7, 22 LTS earlier than 2111.0.11+9Lyrasis DSpaceMailcow Solr DockerManageEngine Servicedesk PlusManagement Services for Element Software and NetApp HCIMcAfee Web Gateway (MWG)Metabase earlier than 0.41.4Micro Focus ArcSight ConnectorsMicro Focus ArcSight ESMMicro Focus ArcSight IntelligenceMicro Focus ArcSight LoggerMicro Focus ArcSight ReconMicro Focus ArcSight Transformation HubMicro Focus Data ProtectorMicro Focus Silk PerformerMicro Focus Silk TestMicrosoft Azure DevOps ServerMicrosoft Cosmos DB Kafka ConnectorMicrosoft Defender for IoTMicrosoft Events Hub ExtensionMicrosoft Kafka Connect for Azure Cosmo DBMicrosoft Minecraft Java EditionMicrosoft Team Foundation ServerMitel Interaction Recording (MIR)Mitel MiVoice Business EX and MiConfig WizardMitel MiVoice MX-ONEMobileIron CoreMobileIron Reporting Database (RDB)MobileIron SentryMongoDB Atlas SearchMulesoft Anypoint StudioMulesoft CloudhubMulesoft Mule AgentMulesoft Mule RuntimeMultiple NetApp productsN-able RMMN-able Risk IntelligenceNAKIVO See linkNEC HYDRAstorNEC Other Storage productsNSA GhidraNVIDIA CUDA Toolkit Nsight Eclipse EditionNVIDIA CUDA Toolkit Visual ProfilerNVIDIA DGX systemsNVIDIA NetQNelson 0.16.185Neo4j 4.1.x earlier than 4.1.11, 4.2.x earlier than 4.2.14, 4.3.x earlier than 4.3.10, 4.4.x earlier than 4.4.3Neo4j Graph DatabaseNetApp 7-Mode Transition ToolNetApp AFF Baseboard Management Controller (BMC) – A700sNetApp ATTO FibreBridge – 6500NNetApp ATTO FibreBridge – 7500NNetApp ATTO FibreBridge – 7600NNetApp Active IQ Unified Manager for LinuxNetApp Active IQ Unified Manager for Microsoft WindowsNetApp Active IQ Unified Manager for VMware vSphereNetApp Active IQ mobile appNetApp Brocade Fabric Operating System FirmwareNetApp Brocade SAN NaviatorNetApp Cloud Backup (formerly AltaVault)NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in)NetApp Cloud Insights Acquisition UnitNetApp Cloud Insights Telegraf AgentNetApp Cloud ManagerNetApp Cloud SecureNetApp Cloud Volumes ONTAP MediatorNetApp Clustered Data ONTAPNetApp Converged Systems Advisor AgentNetApp Data ONTAP operating in 7-ModeNetApp E-Series BIOSNetApp E-Series Performance AnalyzerNetApp E-Series SANtricity Storage ManagerNetApp E-Series SANtricity Web Services (REST API) for Web Services ProxyNetApp Element .NET SDKNetApp Element HealthToolsNetApp Element JAVA SDKNetApp Element Plug-in for vCenter ServerNetApp Element Powershell ToolsNetApp Element Python SDKNetApp FAS/AFF BIOSNetApp FAS/AFF Baseboard Management Controller (BMC) – 8300/8700/A400NetApp FAS/AFF Baseboard Management Controller (BMC) – A250/500fNetApp Global File CacheNetApp HCI Compute Node (Bootstrap OS)NetApp HCI Compute Node BIOSNetApp HCI Storage Node BIOSNetApp Host Utilities – SAN for LinuxNetApp Host Utilities – SAN for WindowsNetApp Inventory Collect ToolNetApp Manageability SDKNetApp MetroCluster Tiebreaker for clustered Data ONTAPNetApp NFS Plug-in for VMware VAAINetApp NextGen APINetApp ONTAP MediatorNetApp ONTAP Select Deploy administration utilityNetApp ONTAP Tools for VMware vSpherNetApp OnCommand InsightNetApp OnCommand System Manager 3.xNetApp OnCommand Unified Manager Core PackageNetApp OnCommand Workflow AutomationNetApp Open Systems SnapVault AgentNetApp SAN Navigator (SANnav)NetApp SANtricity SMI-S ProviderNetApp SANtricity Storage Plugin for vCenterNetApp SANtricity Unified ManagerNetApp SAS FirmwareNetApp SMI-S ProviderNetApp SRA Plugin for LinuxNetApp SRA Plugin for WindowsNetApp Service ProcessorNetApp Single Mailbox RecoveryNetApp Snap Creator FrameworkNetApp SnapCenterNetApp SnapDrive for UnixNetApp SnapDrive for WindowsNetApp SnapManager for ExchangeNetApp SnapManager for Hyper-VNetApp SnapManager for OracleNetApp SnapManager for SAPNetApp SnapManager for SharepointNetApp SolidFire & HCI Management NodeNetApp SolidFire BIOSNetApp SolidFire Baseboard Management Controller (BMC)NetApp SolidFire Plug-in for vRealize Orchestrator (SolidFire vRO)NetApp SolidFire Storage Replication AdapterNetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software)NetApp Storage EncryptionNetApp Storage Services ConnectorNetApp StorageGRID (formerly StorageGRID Webscale)NetApp StorageGRID BIOS SG6060/SGF6024NetApp StorageGRID Baseboard Management Controller (BMC)NetApp StorageGRID9 (9.x and prior)NetApp System Manager 9.xNetApp TridentNetApp XCP NFSNetApp XCP SMBNetCore UnimusNetflix dgs-frameworkNetflix spectatorNew Relic Containerized Private Minion (CPM)New Relic Java AgentNexus Dashboard (formerly Cisco Application Services Engine)Nulab BacklogNulab CacooNulab TypetalkNutanix AHVNutanix AOSNutanix Acropolis (AOS)Nutanix BeamNutanix CalmNutanix Collector PortalNutanix File AnalyticsNutanix FilesNutanix Flow Security CentalNutanix Flow Security CentralNutanix FrameNutanix Karbon Platform ServiceNutanix LeapNutanix ObjectsNutanix Prism CentralNutanix SizerNutanix VolumesNutanix Witness VMOCLCOVHCloud Hosted Private Cloud powered by VMwareOVHCloud Logs Data PlatformOVHCloud ML servingOWASP ZAPOkta On-Prem MFA AgentOkta RADIUS Server AgentOkta Radius Server AgentOneSpan Authentication ApplianceOneSpan Authentication ServerOneSpan Digipass GatewayOneSpan Mobile Security SuiteOneSpan SignOpen Text Content ServerOpen Text Extended ECM for Microsoft Office 365OpenMRS TalkOpenNMS Horizon (including derived Sentinels)OpenNMS Meridian (including derived Minions and Sentinels)OpenNMS Minion applianceOpenSearch earlier than 1.2.1Oracle Database ApplianceOracle Enterprise ManagerOracle Exadata Storage Server SoftwareOracle Exalogic Elastic CloudOracle Fusion MiddlewareOracle Policy Automation (OPA)Oracle Private Cloud ApplianceOracle SQL DeveloperOracle Secure BackupOracle StorageTek Tape AnalyticsOracle Sun StorageTek Tape Library ACSLSOracle WebLogic ServerOracle ZFS Storage Appliance KitOracle Zero Data Loss Recovery ApplianceOrchestrator, Silver Peak GMSOxygenXML AuthorOxygenXML DeveloperOxygenXML EditorOxygenXML Oxygen Content FusionOxygenXML Oxygen Feedback EnterpriseOxygenXML Oxygen License ServerOxygenXML Oxygen PDF ChemistryOxygenXML Oxygen SDKOxygenXML Plugins (see advisory link)OxygenXML Publishing EngineOxygenXML Web AuthorOxygenXML WebHelpPTC Axeda PlatformPTC FlexPLMPTC IntellicusPTC Servigistics Service Parts ManagementPTC Servigistics Service Parts PricingPTC ThingsWorx AnalyticsPTC ThingsWorx PlatformPTC Windchill PDMLinkPTV Group Map&MarketPTV Group PTV Content Update ServicePTV Group PTV DeveloperPTV Group PTV MaaS ModellerPTV Group PTV Route Optimiser CLPTV Group PTV Route Optimiser STPTV Group PTV Route Optimizer SaaS / DemonstratorPTV Group PTV TLN planner internetPTV Group PTV Visum PublisherPTV Group PTV xServerPagerDuty RundeckPagerDuty SaaSPalantir AI Inference Platform (AIP)Palantir FoundryPalantir GothamPalo Alto Exact Data Matching CLIPalo Alto PAN-OS for PanoramaPalo-Alto Networks Exact Data Matching CLIPalo-Alto Networks PAN-OS for PanoramaPega PlatformPersonioPexip ServicePhilips Event Analytics (All Vue PACS Versions)Philips HealthSuite MarketplacePhilips IntelliBridge EnterprisePhilips IntelliSpace EnterprisePhilips IntelliSpace Precision MedicinePhilips Performance BridgePhilips PinnaclePhilips Protocol AnalyticsPhilips Protocol ApplicationsPhilips RIS ClinicPhilips Report Analytics (All Vue PACS Versions)Philips Scanner Protocol ManagerPhilips Tasy EMRPhilips Universal Data Manager (UDM)Philips VuePACSPhoenix Contact Cloud ServicesPing Identity PingAccessPing Identity PingCentralPing Identity PingFederatePing Identity PingIntelligencePolycom Poly Clariti Core/Edge (a.k.a. DMA/CCE)Portex earlier than 3.0.2Proofpoint Archiving ApplianceProofpoint Archiving BackendProofpoint Cloud App Security BrokerProofpoint Cloudmark Cloud/Cloudmark HybridProofpoint Compliance GatewayProofpoint Email ContinuityProofpoint Email Protection on Demand (PoD), including Email DLP and Email EncryptionProofpoint Email Security RelayProofpoint Essentials ArchiveProofpoint Insider Threat Management SaaSProofpoint Secure Email RelayProofpoint Security Awareness TrainingProofpoint SentrionProofpoint SocialPatrolProofpoint Web GatewayProofpoint Web SecurityProofpoint mail Protection On-Premises (PPS), including Email DLP and Email EncryptionPure Storage Cloud Block StorePure Storage Cloud BlockstorePure Storage Flash ArrayPure Storage FlashArrayPure Storage FlashBladePure Storage PURE VM CollectorPure Storage PortWorxPure Storage PortworxPure Storage VM Analytics OVA CollectorQMATIC Appointment BookingQMATIC InsightsQNAP See linksQSAN See linkQconferencing FaceTalkQlikTech International Qlik CatalogRapid7 InsightOps DataHubRapid7 InsightOps r77insight_java Logging LibaryRapid7 InsightOps r7insight_java logging libraryRapid7 Logentries DataHubRapid7 Logentries le_java Logging LibaryRapid7 Logentries le_java logging libraryReal-Time Innovations (RTI) RTI Micro Application Generator (MAG)Red Hat CodeReady StudioRed Hat Data GridRed Hat Descision Manager 7Red Hat Integration Camel KRed Hat Integration Camel QuarkusRed Hat JBoss A-MQ StreamingRed Hat JBoss Enterprise Application PlatformRed Hat JBoss Fuse 7Red Hat OpenShift Container Platform 4 openshift4/ose-logging-elasticsearch6Red Hat OpenShift Container Platform 4 openshift4/ose-metering-hiveRed Hat OpenShift Container Platform 4 openshift4/ose-metering-prestoRed Hat OpenShift Container Platform 4.6 openshift4/ose-metering-prestoRed Hat OpenShift Container Platform 4.7 openshift4/ose-metering-prestoRed Hat OpenShift Container Platform 4.8 openshift4/ose-metering-prestoRed Hat OpenShift Logging 5.0 openshift-logging/elasticsearch6-rhel8Red Hat OpenShift Logging 5.2 openshift-logging/elasticsearch6-rhel8Red Hat OpenShift Logging logging-elasticsearch6-containerRed Hat Process AutomationRed Hat Vert.XRedis JedisRevenera FlexNet Publisher 64-bit License Server ManagerRiverbed NetIM 2.xRiverbed Portal 3.xRiverbed Scon EX AnalyticsRiverbed Scon EX DirectorRiverbed UCExpertRockwell Automation FactoryTalk Analytics DataFlowMLRockwell Automation FactoryTalk Analytics DataViewRockwell Automation MES EIGRockwell Automation Warehouse ManagementRuckus FlexMasterRuckus SmartZone 300 (SZ-300)Ruckus UnleashedRuckus Virtual SmartZone (vSZ)RuneCast AnalyzerSAP Customer Checkout PoS / managerSAP Hana CockpitSAP XS Advanced RuntimeSAS Institute SAS ProfileSBT earlier than 1.5.6SOS (Berlin) JobschedulerSUSE Enterprise StorageSUSE HPE Helion OpenstackSUSE OpenStack CloudSUSE Openstack CloudSchneider Electric EASYFITSchneider Electric EcoStruxure IT ExpertSchneider Electric EcoStruxure IT GatewaySchneider Electric Ecoreal XLSchneider Electric Facility Expert Small BusinessSchneider Electric MSESchneider Electric NEW630Schneider Electric NetBotz750/755Schneider Electric SDK BOMSchneider Electric SDK-DocgenSchneider Electric SDK-TNCSchneider Electric SDK-UMSSchneider Electric SDK3D-2DRendererSchneider Electric SDK3D-360WidgetSchneider Electric SDK3D2DRendererSchneider Electric SDK3D360WidgetSchneider Electric SNC-APISchneider Electric SNC-CMMSchneider Electric SNC-SEMTECHSchneider Electric SNCSEMTECHSchneider Electric SPIMV3Schneider Electric SWBEditorSchneider Electric SWBEngineSchneider Electric Select and Config DATASchneider Electric Wiser by SE platformScripting Tools for Windows PowerShell (HPEiLOCmdlets)Seafile ServerSecurity Onion Solutions Security OnionSentinel Professional Services components (both Thales hosted & hosted on-premises by customers)Siemens Healthineers MAGNETOM Altea NUMARIS/X VA20ASiemens Healthineers MAGNETOM Free.Max NUMARIS/X VA40Siemens Healthineers MAGNETOM Lumina NUMARIS/X VA20ASiemens Healthineers MAGNETOM Sola NUMARIS/X VA20ASiemens Healthineers MAGNETOM Sola fit NUMARIS/X VA20ASiemens Healthineers MAGNETOM Vida fit NUMARIS/X VA20ASiemens Healthineers Somatom Emotion Som5 VC50Siemens Healthineers Somatom Scope Som5 VC50Single Sign-On for VMware Tanzu Application ServiceSmartbear SoapUISnow Software Snow CommanderSnow Software VM Access ProxySolarWinds Database Performance Analyzer (DPA)SolarWinds Server & Application Monitor (SAM)Soliton Systems MailZen Management - Cloud ServiceSoliton Systems MailZen Management Portal - On-PremiseSoliton Systems MailZen Push ServerSonarSource SonarCloudSonicWall Email SecuritySonicWall NSM On-PremiseSophos Cloud OptixSophos Mobile EAS ProxySplunk Add-On for JBoss App ID 2954Splunk Add-On for Java Management Extensions App ID 2647Splunk Add-On: JBossSplunk Add-On: Java Management ExtensionsSplunk Add-On: TomcatSplunk Connect for KafkaSplunk Data Stream ProcessorSplunk Enterprise (including instance types like Heavy Forwarders)Splunk IT Essentials Work App ID 5403Splunk IT Service Intelligence (ITSI)Splunk Logging Library for JavaSplunk OVA for VMWare Metrics App ID 5096Splunk On-call / VictorOpsSplunk Stream Processor ServiceSplunk UBA OVA SoftwareSplunk VMWare OVA for ITSI App ID 4760Spring Cloud Gateway for VMware TanzuSpring Cloud Services for VMware TanzuStardog earlier than 7.8.1Storage Center - Dell Storage ManagerStormShield Visibility CenterStratodesk NoTouchSumo logic Sumu logicSuperMicro Supermicro Power Manager (SPM)Superna EyeglassSyncRO Soft SRL Batch Document ConverterSyncRO Soft SRL Git ClientSyncRO Soft SRL Oxygen Feedback EnterpriseSyncRO Soft SRL Oxygen License ServerSyncRO Soft SRL Oxygen PDF ChemistrySyncRO Soft SRL Oxygen SDKSyncRO Soft SRL Oxygen Web Author Test Server Add-onSyncRO Soft SRL Oxygen XML AuthorSyncRO Soft SRL Oxygen XML Content FusionSyncRO Soft SRL Oxygen XML DeveloperSyncRO Soft SRL Oxygen XML EditorSyncRO Soft SRL Oxygen XML Publishing EngineSyncRO Soft SRL Oxygen XML Web AuthorSyncRO Soft SRL Oxygen XML WebHelpSyncRO Soft SRL Web Author PDF PluginSyncRO Soft SRL XSD to JSON Schema ConverterSysAid earlier than 22.1.10THK Group FlinQ ForesightTP-Link Omada SDN Controller (Linux)TP-Link Omada SDN Controller (Windows)TPLink Omega ControllerTableau BridgeTableau DesktopTableau PrepTableau Public Desktop ClientTableau ReaderTableau ServerTalend Component KitTealiumTeamviewer IoT, Engage, FrontlineTerraMaster See linkTesorion SOC-appliances and softwareThales CADP/SafeNet Protect App (PA) - JCEThales CipherTrust Batch Data Transformation (BDT) 2.3Thales CipherTrust Cloud Key Manager (CCKM) ApplianceThales CipherTrust Vaulted Tokenization (CT-V) / SafeNet Tokenization ManagerThales CipherTrust/SafeNet PDBCTLThales Crypto Command Center (CCC)Thales Data Platform (TDP)(DDC)Thales SafeNet Vaultless TokenizationThales Sentinel EMS Enterprise aaSThales Sentinel LDK EMS (LDK-EMS)Thales Sentinel LDKaas (LDK-EMS)Thales Sentinel SCLThomson Reuters HighQ ApplianceTintri VMstore TxOSTosiboxTrend Micro Cloud App SecurityTrend Micro Deep Discovery DirectorTrend Micro Email Security & HESTrend Micro Sandbox as a ServiceTrend Micro TippingPoint Threat Management Center (TMC)Trend Micro Vision OneTrend Micro Web SecurityTrimble eCognitionTripwire Anyware SCMTripwire Configuration Manager SaaSTripwire Connect (on-prem)Tripwire Connect SaaS (cloud)Tripwire State AnalyzerTrueNAS See linkUSoft 9.x earlier than 9.1 and 10.x earlier than 10.0Ubiquiti UniFi Network ApplicationUnified Communications Manager / Cisco Unified Communications Manager Session Management EditionUnify Hipath DS-WinVMware App MetricsVMware Carbon Black Cloud Workload ApplianceVMware Carbon Black EDR serverVMware Cloud Director Object Storage ExtensionVMware Cloud Provider Lifecycle ManagerVMware Greenplum TextVMware HCXVMware Harbor Container Registry for TKGIVMware Healthwatch for Tanzu Application ServiceVMware HorizonVMware Identity ManagerVMware Integrated OpenStackVMware NSX Data Center for vSphereVMware NSX-T Data CenterVMware NSX-T Intelligence ApplianceVMware SD-WAN VCOVMware Site Recovery ManagerVMware Smart Assurance M&RVMware Smart Assurance NCMVMware Smart Assurance SAM [Service Assurance Manager]VMware Spring Cloud Gateway for KubernetesVMware Tanzu Application Services for VMsVMware Tanzu GemFireVMware Tanzu Greenplum Platform Extension FrameworkVMware Tanzu Kubernetes Grid Integrated EditionVMware Tanzu Observability ProxyVMware Tanzu Observability by Wavefront NozzleVMware Tanzu Operations ManagerVMware Tanzu SchedulerVMware Telco Cloud OperationsVMware Unified Access Gateway (UAG)VMware Workspace ONE AccessVMware vCenter Server - OVAVMware vCenter Server - WindowsVMware vRealize AutomationVMware vRealize Business for CloudVMware vRealize Log InsightVMware vRealize Network InsightVMware vRealize OperationsVMware vRealize OrchestratorVarian SmartConnect solutionVeeam productsVeritas Aptare IT AnalyticsVeritas Backup ExecVeritas CloudPointVeritas MSDP – Media Server Deduplication Engine (NetBackup Appliance)Veritas NetBackup ApplianceVeritas NetBackup ClientVeritas NetBackup CloudCatalyst Media ServerVeritas NetBackup CloudPointVeritas NetBackup Flex ScaleVeritas NetBackup Media ServerVeritas NetBackup OpsCenterVeritas NetBackup Primary ServerVeritas NetBackup Resiliency PlatformVmware VSAN – VMware vCenter ServerVmware VSAN – VMware vSphere ESXiWAGO Smart ScriptWallix Access ManagerWatchGuard AuthPointWatchGuard Threat Detection and ResponseWatchGuard Wi-Fi CloudWibu Systems CodeMeter Cloud LiteWibu Systems CodeMeter Keyring for TIA PortalWitFoo PrecinctXerox DocuShare using Solr searchXylem AquatalkXylem AvensorXylem CloudXylem Configuration change completeXylem Edge Gateway (xGW)Xylem Sensus AnalyticsXylem Sensus Automation Control Configuration change completeXylem Sensus Cathodic Protection Mitigation in process Mitigation in processXylem Sensus FieldLogic LogServerXylem Sensus Lighting ControlXylem Sensus NetMetrics Configuration change completeXylem Sensus RNI On PremXylem Sensus RNI SaasXylem Sensus SCSXylem Smart IrrigationXylem Water Loss Management (Visenti)Yellowfin 8.0.10.3, 9.7.0.2Zadara productsZeiss Cataract SuiteZeiss EQ WorkplaceZeiss FORUMZeiss Glaucoma WorkplaceZeiss Laser Treatment WorkplaceZeiss Retina WorkplaceZendeskZscalerZyxel NetAtlas Element Management System (EMS)iGrafixopenHAB 3.0.4, 3.1.1syntevo DeepGitsyntevo SmartGitsyntevo SmartSVNsyntevo SmartSynchronizevRO Plugin for Dell EMC PowerMaxvRO Plugin for Dell EMC PowerScalevRealize Operations Tenant App for VMware Cloud DirectorvRealize Orchestrator (vRO) Plug-ins for Dell EMC Storage

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

0.975 High

EPSS

Percentile

100.0%