# Log4Shell exploitation observed hitting Japan

Published: 2021-12-13 · Severity: critical
Canonical: https://vorant.io/reports/1b470680-c13e-510c-94c6-02d7cc5e867a/log4shell-exploitation-observed-hitting-japan

> IPA warns that attacks exploiting the Apache Log4j remote code execution vulnerability (Log4Shell) have been observed in Japan and urges immediate patching.

Japan's IPA (Information-technology Promotion Agency) issued an alert on the Apache Log4j vulnerability commonly known as Log4Shell, warning that exploitation attempts believed to abuse this flaw have been observed domestically. The advisory notes the vulnerability allows a remote attacker to execute arbitrary commands by sending specially crafted data to systems using vulnerable versions of the Log4j Java logging library, affecting Log4j 2.x versions prior to 2.15.0 (with some exceptions in the 2.12 branch).

The advisory clarifies that Log4j 1.x, though end-of-life, is not affected under default configuration since it lacks the JNDI lookup feature, though certain specific configurations could still expose risk. IPA recommends organizations update immediately to patched versions (2.17.0 or 2.12.3, which also address a related denial-of-service issue tracked as CVE-2021-45105) and apply interim mitigations if immediate patching is not possible, including restricting outbound network connections to reduce the impact of exploitation attempts. The bulletin was updated multiple times between December 13-27, 2021 as vendor guidance and mitigation details evolved.

## Mentioned in this report

- Vulnerabilities: CVE-2021-45105

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2021/alert20211213.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/1b470680-c13e-510c-94c6-02d7cc5e867a/log4shell-exploitation-observed-hitting-japan.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
