Qualys Offers Free Access to Its Web Application Analysis Application to Help Organizations Quickly Find Log4Shell Vulnerabilities


HOST CITY, California, December 17, 2021 / PRNewswire / – Qualys, Inc. (NASDAQ: QLYS), a pioneer and leading provider of innovative cloud-based IT, security and compliance solutions, today announced that it is making its Web Application Scanning solution (WAS) available free for 30 days, to help businesses protect themselves against Log4Shell.

The Apache Log4Shell zero-day RCE vulnerability has raised alarm bells for businesses around the world, with US government officials calling it “one of the most serious flaws they have seen.” The vulnerability poses potential threats to nearly any web application, with the list of known exploits growing daily.

The scanning capabilities of web applications are essential to detect these vulnerabilities as they simulate the attack of Log4Shell exploits. To help customers protect themselves against this threat, Qualys creates its WAS application, which scans web applications and APIs for Log4Shell (CVE-2021-44228), available free for 30 days.

Qualys WAS enables precise detections of applications vulnerable to Log4Shell thanks to its advanced out-of-band detection mechanisms. To identify vulnerable sites, WAS uses specially designed payloads to simulate the same attack model used by malicious actors. Vulnerable sites are quickly and easily identified for remediation, shutting the door on attackers before they even know you are exposed.

“Log4Shell is the most alarming vulnerability we have seen in the past decade and helping the community tackle this unprecedented threat is at the forefront of our attention,” said Sumedh Thakar Chairman and CEO of Qualys. “Many organizations are scrambling to find ways to detect their exposure to Log4Shell. We hope that the free access to our application along with the open source scripts we have released will help security teams quickly assess and secure their external web attack surface.

To sign up for the free 30-day WAS service, go to qualys.com/was-log4j-trial. For more information on using WAS to detect Log4Shell, read our blog, Is your web application exploitable by the Log4 Shell vulnerability?

Additional resources

About Qualys
Qualys, Inc. (NASDAQ: QLYS) is a pioneer and leading provider of innovative cloud-based IT, security and compliance solutions with more than 19,000 active customers in over 130 countries, including a majority of each of the Forbes Global 100 and Fortune 100 rankings Qualys helps organizations streamline and consolidate their security and compliance solutions on a single platform and integrate security into digital transformation initiatives for greater agility, better business results and substantial savings.

The Qualys cloud platform and its integrated cloud applications provide businesses with continuous critical security information, enabling them to automate all auditing, compliance and protection of IT systems and web applications on the web. site, endpoints, cloud, containers and mobile environments. Founded in 1999 as one of the first SaaS security companies, Qualys has established strategic partnerships with leading cloud providers such as Amazon Web Services, Microsoft Azure, and Google Cloud Platform, as well as vendors managed services and consulting organizations including Accenture, BT, Cognizant Technology Solutions, Deutsche Telekom, DXC Technology, Fujitsu, HCL Technologies, IBM, Infosys, NTT, Optiv, SecureWorks, Tata Communications, Verizon and Wipro. The company is also a founding member of the Cloud Security Alliance. For more information, please visit www.qualys.com.

Qualys and the Qualys logo are registered trademarks of Qualys, Inc. All other products or names may be trademarks of their respective companies.

Media contact:
Jackie Dutton
Qualys
[email protected]

SOURCE Qualys, Inc.

Related links

http://www.qualys.com


Comments are closed.