Tungsten Automation Knowledge

Tungsten Automation products and Apache Log4j2 vulnerability information

000019222 · Troubleshooting · Last Updated: Sep 10, 2026

Products not listed on this page have been evaluated and are not vulnerable.

Tungsten Automation is aware of the recently disclosed Apache Log4j2 vulnerabilities (CVE-2021-44228, CVE2021-45046, CVE2021-45105). The following products are using the potentially vulnerable Log4j2 version. We are evaluating the use of Log4j2 in the above products and will create patches as needed, as a priority.

Affected ProductsRemediation Status Community Product Discussion URL Bookmark your product's post for any future updates
Robotic Process Automation (RPA) 10.7-11.2Patches are available. See   RPA CVE-2021-44228 log4j Security Exploit Information article. Robotic Process Automation Release Announcements
Communication Manager (KCM) 5.3-5.5Patches are available. See log4j vulnerability in Communications Manager article. Communications Manager Release Announcements
Device Web Service (DWS) 10.2The DWS is used with AutoStore, Equitrac, and Output Manager when deploying embedded clients, including the Unified Client.See ControlSuite and the Log4j vulnerability CVE-2021-44228 for more information. ControlSuite Release Announcements
Device Web Service (DWS) 5.11See ControlSuite and the Log4j vulnerability CVE-2021-44228 for more information. ControlSuite Release Announcements
eCopy ShareScan 6.xUntil the ShareScan patches are ready, follow the steps in the ShareScan and Log4j vulnerability (CVE-2021-44228) -  article. MFD and Productivity Release Announcements
Invoice PortalPotential vulnerability remediated ReadSoft Release Announcements
Supplier PortalPotential vulnerability remediated ReadSoft Release Announcements
AP Essentials (formerly ReadSoft Online)AP - Essentials (formerly ReadSoft Online) does not have native dependencies on Log4j. One third-party component has been identified to utilize Log4j. has been patched and updated according to the supplier's recommendations. ReadSoft Release Announcements
ExderPotential vulnerability remediated ReadSoft Release Announcements
Device Registration Service (DRS) See ControlSuite and the Log4j vulnerability CVE-2021-44228 for more information. ControlSuite Release Announcements

Applies to

ProductVersionBuildEnvironmentHardware
General Support

Sections recovered from body HTML: none detected.

https://aio-eus-uat-cae-aif-app14-local.redglacier-35d7ee4f.eastus.azurecontainerapps.io/article/19222 | Article 000019222 | Printed Sep 30, 2026

Back to the article · use your browser's Print command, or save the PDF.