Netskope Threat Labs

CVE-2021-44228

ATP Sandbox Adv. HeuristicsNetskope IPS

This detection identifies exploitation attempts targeting CVE-2021-44228, which has a CRITICAL severity rating. Apache Log4j2 2.0-beta9 through 2.15.0 does not protect JNDI features used in configuration, log messages, and parameters against cyberattacker controlled LDAP and other JNDI endpoints. A cyberattacker who can control log messages or their parameters can execute arbitrary code loaded from LDAP servers when the configuration enables message lookup substitution, an issue known as Log4Shell. Later releases turned the behavior off and then removed it entirely, and the vulnerability affects only log4j-core.

First seen
July 2022
Last seen
October 2026
Alert Name
Binary.Exploit.CVE-2021-44228
ByteCode-JAVA.Exploit.CVE-2021-44228
Document-HTML.Exploit.CVE-2021-44228
Linux.Exploit.CVE-2021-44228
Package.Exploit.CVE-2021-44228
Win32.Exploit.CVE-2021-44228
Win64.Exploit.CVE-2021-44228