Free 30-day use of the Qualys Web Application Scanning App to help enterprises quickly find Log4Shell vulnerabilities
Qualys, Inc. (NASDAQ: QLYS), a pioneer and leading provider of highly innovative cloud-based IT security and compliance solutions, has made its Web Application Scanning (WAS) solution available free of charge for 30 days to help businesses protect themselves from Log4Shell.
Apache's zero-day RCE Log4Shell vulnerability has raised alarms at companies around the world, with US government officials calling it "one of the most serious vulnerabilities we've ever seen." The vulnerability poses potential threats to almost every single web application, with the list of known exploits growing by the day.
The scanning capabilities offered by web applications are essential to detect these vulnerabilities, as they simulate the attack of Log4Shell exploits. To help its customers protect themselves from this threat, Qualys has made its WAS App available free of charge for 30 days, which analyzes web applications and APIs for the Log4Shell vulnerability (CVE-2021-44228).
Qualys WAS performs accurate detections of applications vulnerable to Log4Shell through advanced out-of-band detection mechanisms. To identify vulnerable sites, WAS uses specially crafted payloads to simulate the same attack model used by malicious actors. Vulnerable sites are thus quickly and easily identified for appropriate remediation activities, closing the door to attackers before users even realize they have been exposed.
“Log4Shell is the most damaging vulnerability we have detected in the last decade and helping the community combat this unprecedented threat is one of our priorities,” he highlighted Sumedh Thakar President and CEO of Qualys. “Many organizations are scrambling to find ways to detect their exposure to Log4Shell, and we hope that free access to our app, along with the open-source scripts we have released, will help security teams quickly assess and secure their external web attack surface.”
To access the free WAS service for 30 days, go to qualys.com/was-log4j-trial. For more information on using WAS to detect the Log4Shell vulnerability, read our blog, Your web application could be exploited by the Log4 Shell vulnerability?






