A high severity vulnerability (CVE-2021-44228) impacting multiple versions of the Apache Log4j2 utility was disclosed publicly on December 9, 2021. The vulnerability impacts Apache Log4j2 versions below 2.15.0. Find the details of this vulnerability documented here: https://logging.apache.org/log4j/2.x/security.html

ManageEngine products bundled with vulnerable Log4j2:

Product nameJar version in bundled dependency
ADManager PlusV2.11.1
ADAudit PlusV2.10.0
DataSecurity PlusV2.10.0
EventLog AnalyzerV2.9.1
M365 Manager PlusV2.11.1
RecoveryManager PlusV2.11.1
Exchange Reporter PlusV2.11.1
Log360V2.9.1
Log360 UEBAV2.11.1
Cloud Security PlusV2.9.1

Please note that we have not identified any exploitable cases due to Log4j2 in the above products as we do not use Log4j directly for logging. But, some of the third parties we use bundle Log4j2 as a dependency. So as an additional safety measure, customers are instructed to apply the mitigation steps listed below:

  1. ADManager Plus 
  2. ADAudit Plus 
  3. DataSecurity Plus 
  4. EventLog Analyzer 
  5. M365 Manager Plus 
  6. RecoveryManager Plus
  7. Exchange Reporter Plus 
  8. Log360
  9. Log360 UEBA (steps detailed in comments of ManageEngine PitStop post here)
  10. Cloud Security Plus (steps detailed in comments of ManageEngine PitStop post here)

*** Other ManageEngine products that are not listed above are not impacted by this vulnerability ***

We are continuing to analyze the issue and will update this advisory if any new information becomes available.For any additional details or assistance, please contact security@manageengine.com

This article is relevant to:
ManageEngineSecurity Advisory

You may be interested in these other recent articles

Live Status Monitoring of the ManageEngine Cloud Services

23 September 2024

This blog details the status of ManageEngine cloud services, such as ServiceDesk Plus cloud. Links to the monitoring pages showing the status can be found…

Read more

Latest Updates for ManageEngine ServiceDesk Plus On-Premise

20 September 2024

Discover the latest ServiceDesk Plus updates, including new features, fixes, and enhancements.

Read more

Creating ServiceDesk Plus Requests From a Microsoft Teams Chat

18 September 2024

Find out how ServiceDesk Plus Cloud can help you create requests directly from a Microsoft Teams chat.

Read more

Latest Updates for ManageEngine ServiceDesk Plus Cloud

17 September 2024

Discover the latest ServiceDesk Plus Cloud updates, including new features, fixes, and enhancements.

Read more

Latest Updates for ManageEngine Endpoint Central

16 September 2024

Discover the latest Endpoint Central updates, including new features, fixes, and enhancements.

Read more