CRITICAL · 9.8

CVE-2022-22965

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR ...

Vulnerability Description

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
VmwareSpring Framework< 5.2.20
OracleJdk>= 9
CiscoCx Cloud Agent< 2.1.0
OracleCommunications Cloud Native Core Automated Test Suite1.9.0
OracleCommunications Cloud Native Core Console1.9.0
OracleCommunications Cloud Native Core Network Exposure Function22.1.0
OracleCommunications Cloud Native Core Network Function Cloud Native Environment1.10.0
OracleCommunications Cloud Native Core Network Repository Function1.15.0
OracleCommunications Cloud Native Core Network Slice Selection Function1.8.0
OracleCommunications Cloud Native Core Policy1.15.0
OracleCommunications Cloud Native Core Security Edge Protection Proxy1.7.0
OracleCommunications Cloud Native Core Unified Data Repository1.15.0
OracleCommunications Policy Management12.6.0.0.0
OracleFinancial Services Analytical Applications Infrastructure8.1.1
OracleFinancial Services Behavior Detection Platform8.1.1.0
OracleFinancial Services Enterprise Case Management8.1.1.0
OracleMysql Enterprise Monitor< 8.0.29
OracleProduct Lifecycle Analytics3.6.1
OracleRetail Xstore Point Of Service20.0.1
OracleSd-Wan Edge9.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-22965?

CVE-2022-22965 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR ...

How severe is CVE-2022-22965?

CVE-2022-22965 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2022-22965?

Check the references section above for vendor advisories and patch information. Affected products include: Vmware Spring Framework, Oracle Jdk, Cisco Cx Cloud Agent, Oracle Communications Cloud Native Core Automated Test Suite, Oracle Communications Cloud Native Core Console.