CVE-2022-22963 KEV EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 99.9% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-09-15.
Description
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 99.94% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | yes — remediate by 2022-09-15 |
| Public exploit | yes |
| Published | 2022-04-01 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability |
|---|---|
| Added | 2022-08-25 |
| Due | 2022-09-15 |
| Vendor / product | VMware Tanzu / Spring Cloud |
| Ransomware use | none reported |
Affected (28)
| Vendor | Product |
|---|---|
| oracle | banking branch |
| oracle | banking cash management |
| oracle | banking corporate lending process management |
| oracle | banking credit facilities process management |
| oracle | banking electronic data exchange for corporates |
| oracle | banking liquidity management |
| oracle | banking origination |
| oracle | banking supply chain finance |
| oracle | banking trade finance process management |
| oracle | banking virtual account management |
| oracle | communications cloud native core automated test suite |
| oracle | communications cloud native core console |
| oracle | communications cloud native core network exposure function |
| oracle | communications cloud native core network function cloud native environment |
| oracle | communications cloud native core network repository function |
| oracle | communications cloud native core network slice selection function |
| oracle | communications cloud native core policy |
| oracle | communications cloud native core security edge protection proxy |
| oracle | communications cloud native core unified data repository |
| oracle | communications communications policy management |
| oracle | financial services analytical applications infrastructure |
| oracle | financial services behavior detection platform |
| oracle | financial services enterprise case management |
| oracle | mysql enterprise monitor |
| oracle | product lifecycle analytics |
| oracle | retail xstore point of service |
| oracle | sd-wan edge |
| vmware | spring cloud function |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Spring Cloud 3.2.2 - Remote Command Execution (RCE) | 2023-07-11 |
References
- http://packetstormsecurity.com/files/173430/Spring-Cloud-3.2.2-Remote-Command-Execution.html
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005
- https://tanzu.vmware.com/security/cve-2022-22963
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-scf-rce-DQrHhJxH
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- http://packetstormsecurity.com/files/173430/Spring-Cloud-3.2.2-Remote-Command-Execution.html
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005
- https://tanzu.vmware.com/security/cve-2022-22963
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-scf-rce-DQrHhJxH
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22963
→ the Explorer · watch your stack · NVD