Detection for CVE-2021-44228 (Log4shell in Apache Tomcat)
Copy link to “Detection for CVE-2021-44228 (Log4shell in Apache Tomcat)”The Network Scanner can now detect if an Apache Tomcat instance is vulnerable to Log4Shell (CVE-2021-44228).
These are the latest updates we've made to our platform. If you have any questions about any of the updates you see below, please feel free to contact us!
The Network Scanner can now detect if an Apache Tomcat instance is vulnerable to Log4Shell (CVE-2021-44228).
Sniper can now exploit an RCE in the Netgear routers (CVE-2020-17409, CVE-2020-27866).
Sniper can now exploit an RCE in the Log4j logging library (CVE-2021-44228).
Added the possibility to chain the Network Scanner within the Pentest Robots.
The Network Scanner can now detect if a server is vulnerable to a RCE vulnerability in the Log4j logging library (CVE-2021-44228).
The Website Scanner can now detect the Apache Log4j vulnerability (CVE-2021-44228).
We added detection for Ruby Code injection in The Deep Website Scanner.
Added detection for Broken Authentication while running an authenticated website scan in the Website Scanner.
Sniper can now exploit an RCE in Apache OFBiz (CVE-2021-26295).
We added the possibility to see the target description in the All Scans page and the scheduler page. To enable it, check View settings -> Show target description.
Password Auditor can now discover weak credentials for the Redis service.
The Network Scanner can now detect if a Microsoft Exchange server is vulnerable to Pre-Auth POST Based Reflected XSS (CVE-2021-41349).
We added detection for Perl Code injection in The Deep Website Scanner.
Sniper can now exploit an RCE in the Apache Tomcat HTTP Server (CVE-2017-12617).
Sniper can now exploit an RCE in Exim mail server (CVE-2019-10149).
Sniper can now exploit an RCE in Laravel PHP framework (CVE-2021-3129).
We added detection for Python Code injection in The Deep Website Scanner.
Sniper can now exploit an RCE in the Apache Struts 2 Framework (CVE-2019-0230).
The Password Auditor now produces findings. Check the Findings page, where you can modify them and create editable reports.
We have a new scan option for the Network Scanner - Sniper scan, a light scan that allows you to check only for the highly exploitable vulnerabilities in a non-intrusive way.