S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-44228 Scanner

CVE-2021-44228 scanner - Remote Code Execution (RCE) vulnerability in Apache Log4j2

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
5.1k
Continuously Checked
assets under CS
5
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-44228
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Apache Log4j2by Apache Software Foundation
AFFECTED< log4j-core*SAFE ✓≥ log4j-core*
Updated Aug 21, 2026View on NVD →
Detail

Apache Log4j2 is a logging framework that offers many powerful features and a flexible configuration. It is widely used in Java-based applications and provides developers with the ability to log messages at different levels. Specifically, it allows logging to files, console output, network streams, and even databases. The straightforward APIs and the variety of appenders make it one of the most popular logging frameworks in the Java ecosystem.

Recently, a severe vulnerability code CVE-2021-44228 has been discovered in Apache Log4j2 versions ranging from 2.0-beta9 to 2.15.0, which can enable remote attackers to execute arbitrary code on an affected system. The flaw exists in the codebase for the JNDI (Java Naming and Directory Interface) features. This problem is primarily the result of the availability of these features to users without security checks, leading to an exploitation of the vulnerability through the use of user-supplied configuration files and log messages.

If left unaddressed, this vulnerability could lead to an attacker executing arbitrary code on the target system. Attackers can use this code to install malware, steal sensitive data, or use the system as part of a botnet. The security flaw is particularly impactful in environments where the JNDI-Lookup feature is enabled, as this can allow an attacker to execute malicious code by including it in the attribute values of a log message or the parameters of a method call. This can result in complete system compromise if the attack successfully exploits the vulnerability.

Thanks to the Pro features of s4e.io, you can easily and quickly learn about vulnerabilities in your digital assets. The platform offers continuous monitoring, alerting, and expert guidance, enabling proactive risk management for your organization. Being proactive in your approach to security is the most effective way to prevent breaches and mitigate risks that may arise.

 

REFERENCES

Solution Advice

Fortunately, there are several measures that can be taken to protect against this vulnerability:

  • Upgrade to a secure version of Apache Log4j2 or install the latest security patches.
  • If possible, disable the JNDI-Lookup feature and use the Log4j2 configuration interface to configure appenders, loggers, and filters instead of configuration files.
  • Remove or disable any configuration files that use the JNDI-Lookup feature.
  • Block incoming traffic to the JNDI endpoint port using a firewall or network access control list (NACL).
  • Implement logging best practices, such as ensuring that all loggers are set to the appropriate level, and using appropriate logging patterns to ensure that actionable information can be discerned from the logs generated.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.