CVE-2022-22965 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 99.6% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-04-25.
Description
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 99.64% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | yes — remediate by 2022-04-25 |
| Public exploit | none known |
| Published | 2022-04-01 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Spring Framework JDK 9+ Remote Code Execution Vulnerability |
|---|---|
| Added | 2022-04-04 |
| Due | 2022-04-25 |
| Vendor / product | VMware / Spring Framework |
| Ransomware use | none reported |
Affected (39)
| Vendor | Product |
|---|---|
| cisco | cx cloud agent |
| oracle | commerce platform |
| oracle | communications cloud native core automated test suite |
| oracle | communications cloud native core binding support function |
| oracle | communications cloud native core console |
| oracle | communications cloud native core network exposure function |
| oracle | communications cloud native core network function cloud native environment |
| oracle | communications cloud native core network repository function |
| oracle | communications cloud native core network slice selection function |
| oracle | communications cloud native core policy |
| oracle | communications cloud native core security edge protection proxy |
| oracle | communications cloud native core unified data repository |
| oracle | communications policy management |
| oracle | communications unified inventory management |
| oracle | financial services analytical applications infrastructure |
| oracle | financial services behavior detection platform |
| oracle | financial services enterprise case management |
| oracle | jdk |
| oracle | mysql enterprise monitor |
| oracle | product lifecycle analytics |
| oracle | retail bulk data integration |
| oracle | retail customer management and segmentation foundation |
| oracle | retail financial integration |
| oracle | retail integration bus |
| oracle | retail merchandising system |
| oracle | retail xstore point of service |
| oracle | sd-wan edge |
| oracle | weblogic server |
| siemens | operation scheduler |
| siemens | simatic speech assistant for machines |
| siemens | sinec network management system |
| siemens | sipass integrated |
| siemens | siveillance identity |
| veritas | access appliance |
| veritas | flex appliance |
| veritas | netbackup appliance |
| veritas | netbackup flex scale appliance |
| veritas | netbackup virtual appliance |
| vmware | spring framework |
References
- http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.html
- http://packetstormsecurity.com/files/167011/Spring4Shell-Spring-Framework-Class-Property-Remote-Code-Execution.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-254054.pdf
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005
- https://tanzu.vmware.com/security/cve-2022-22965
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.html
- http://packetstormsecurity.com/files/167011/Spring4Shell-Spring-Framework-Class-Property-Remote-Code-Execution.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-254054.pdf
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005
- https://tanzu.vmware.com/security/cve-2022-22965
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67
- https://www.kb.cert.org/vuls/id/970766
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22965
→ the Explorer · watch your stack · NVD