peter bassill · operator
$ cve CVE-2022-22947 JSON

CVE-2022-22947 KEV EXPLOIT

10.0
CRITICAL · CVSS 3.1 · EPSS 98.3% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-06.

Description

In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS98.25% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-94
On CISA KEVyes — remediate by 2022-06-06
Public exploityes
Published2022-03-03
Last modified2026-06-17

CISA KEV

NameVMware Spring Cloud Gateway Code Injection Vulnerability
Added2022-05-16
Due2022-06-06
Vendor / productVMware / Spring Cloud Gateway
Ransomware usenone reported

Affected (10)

VendorProduct
oraclecommerce guided search
oraclecommunications cloud native core binding support function
oraclecommunications cloud native core console
oraclecommunications cloud native core network exposure function
oraclecommunications cloud native core network function cloud native environment
oraclecommunications cloud native core network repository function
oraclecommunications cloud native core network slice selection function
oraclecommunications cloud native core security edge protection proxy
oraclecommunications cloud native core service communication proxy
vmwarespring cloud gateway

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD