Last updated on: 5th May, 2022
ManageEngine products bundled with vulnerable Log4j2 (as of 13th December, 2021):
Product name | Jar version in bundled dependency |
ADAudit Plus | V2.10.0 |
DataSecurity Plus | V2.10.0 |
EventLog Analyzer | V2.9.1 |
M365 Manager Plus | V2.11.1 |
RecoveryManager Plus | V2.11.1 |
Exchange Reporter Plus | V2.11.1 |
Log360 | V2.9.1 |
Log360 UEBA | V2.11.1 |
Cloud Security Plus | V2.9.1 |
M365 Security Plus | V2.11.1 |
Analytics Plus | V2.7 |
Please note that we have not identified any exploitable cases due to Log4j2 in the above products as we do not use Log4j directly for logging. But, some of the third parties we use bundle Log4j2 as a dependency. So as an additional safety measure, customers are instructed to apply the mitigation steps listed below:
Other ManageEngine products that are not listed above are not impacted by this vulnerability.
We are continuing to analyze the issue and will update this advisory if any new information becomes available.