peter bassill · operator
$ cve CVE-2022-22965 JSON

CVE-2022-22965 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 99.6% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-25.

Description

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.64% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-94
On CISA KEVyes — remediate by 2022-04-25
Public exploitnone known
Published2022-04-01
Last modified2026-06-17

CISA KEV

NameSpring Framework JDK 9+ Remote Code Execution Vulnerability
Added2022-04-04
Due2022-04-25
Vendor / productVMware / Spring Framework
Ransomware usenone reported

Affected (39)

VendorProduct
ciscocx cloud agent
oraclecommerce platform
oraclecommunications cloud native core automated test suite
oraclecommunications cloud native core binding support function
oraclecommunications cloud native core console
oraclecommunications cloud native core network exposure function
oraclecommunications cloud native core network function cloud native environment
oraclecommunications cloud native core network repository function
oraclecommunications cloud native core network slice selection function
oraclecommunications cloud native core policy
oraclecommunications cloud native core security edge protection proxy
oraclecommunications cloud native core unified data repository
oraclecommunications policy management
oraclecommunications unified inventory management
oraclefinancial services analytical applications infrastructure
oraclefinancial services behavior detection platform
oraclefinancial services enterprise case management
oraclejdk
oraclemysql enterprise monitor
oracleproduct lifecycle analytics
oracleretail bulk data integration
oracleretail customer management and segmentation foundation
oracleretail financial integration
oracleretail integration bus
oracleretail merchandising system
oracleretail xstore point of service
oraclesd-wan edge
oracleweblogic server
siemensoperation scheduler
siemenssimatic speech assistant for machines
siemenssinec network management system
siemenssipass integrated
siemenssiveillance identity
veritasaccess appliance
veritasflex appliance
veritasnetbackup appliance
veritasnetbackup flex scale appliance
veritasnetbackup virtual appliance
vmwarespring framework

References

→ the Explorer  ·  watch your stack  ·  NVD