Products not listed on this page have been evaluated and are not vulnerable.
Tungsten Automation is aware of the recently disclosed Apache Log4j2 vulnerabilities (CVE-2021-44228, CVE2021-45046, CVE2021-45105). The following products are using the potentially vulnerable Log4j2 version. We are evaluating the use of Log4j2 in the above products and will create patches as needed, as a priority.
| Affected Products | Remediation Status | Community Product Discussion URL Bookmark your product's post for any future updates |
| Robotic Process Automation (RPA) 10.7-11.2 | Patches are available. See RPA CVE-2021-44228 log4j Security Exploit Information article. | Robotic Process Automation Release Announcements |
| Communication Manager (KCM) 5.3-5.5 | Patches are available. See log4j vulnerability in Communications Manager article. | Communications Manager Release Announcements |
| Device Web Service (DWS) 10.2The DWS is used with AutoStore, Equitrac, and Output Manager when deploying embedded clients, including the Unified Client. | See ControlSuite and the Log4j vulnerability CVE-2021-44228 for more information. | ControlSuite Release Announcements |
| Device Web Service (DWS) 5.11 | See ControlSuite and the Log4j vulnerability CVE-2021-44228 for more information. | ControlSuite Release Announcements |
| eCopy ShareScan 6.x | Until the ShareScan patches are ready, follow the steps in the ShareScan and Log4j vulnerability (CVE-2021-44228) - article. | MFD and Productivity Release Announcements |
| Invoice Portal | Potential vulnerability remediated | ReadSoft Release Announcements |
| Supplier Portal | Potential vulnerability remediated | ReadSoft Release Announcements |
| AP Essentials (formerly ReadSoft Online) | AP - Essentials (formerly ReadSoft Online) does not have native dependencies on Log4j. One third-party component has been identified to utilize Log4j. has been patched and updated according to the supplier's recommendations. | ReadSoft Release Announcements |
| Exder | Potential vulnerability remediated | ReadSoft Release Announcements |
| Device Registration Service (DRS) | See ControlSuite and the Log4j vulnerability CVE-2021-44228 for more information. | ControlSuite Release Announcements |
| Product | Version | Build | Environment | Hardware |
|---|---|---|---|---|
| General Support |