Qualys WAS Detects Log4Shell (CVE-2021-44228) in Web Applications
Qualys Web Application Scanning (WAS) now detects the critical Log4Shell vulnerability (CVE-2021-44228) using QID 150440 and 150441, leveraging Out-of-Band detection via Qualys Periscope.

Overview
On December 9, 2021, a critical remote code execution vulnerability (CVE-2021-44228) was disclosed in Apache Log4j2, affecting versions 2.x through 2.15.0-rc1. With a CVSSv3 score of 10, this flaw allows remote attackers to execute arbitrary code on systems using the Log4j2 library. Active exploitation in the wild prompted Qualys to release detection capabilities in its Web Application Scanning (WAS) module.
Detection Methodology
Qualys WAS uses QID 150440 and 150441 to detect vulnerable web applications. The scanner injects JNDI lookup payloads into multiple HTTP headers (e.g., User-Agent, X-Forwarded-For, Cookie) and leverages an Out-of-Band (OOB) detection mechanism. When a vulnerable application processes the payload, it makes a DNS callback to Qualys Periscope, which verifies the request and confirms the vulnerability.
Affected Applications
- Apache Struts2
- Apache Solr
- Apache Druid
- Apache OFBiz
- Apache JSPWiki
Remediation
Users should upgrade to Apache Log4j 2.17.1, which addresses CVE-2021-44228, CVE-2021-45046, and CVE-2021-44832.