BlackTreeCVE Intelligence
← Back to the CVE catalogue
Full vulnerability report · 2022
CVE-2022-22965High confidence

Spring Framework JDK 9+ Remote Code Execution Vulnerability

VMware · Spring Framework

9.8CriticalCVSS 3.1
Recommended action
Patch only the product branches with a verified fix

CISA confirms exploitation in the wild and lists 2022-04-25 as the remediation due date. Verified remediation exists for at least one product or source, but 11 structured product or package states remain unresolved. Apply remediation only to the exact product branch confirmed by its source.

Fix availability varies by product
R
Operational reassessment

Published severity in operational context

Open reassessment dashboard →
Published severityCriticalOperational priority:Critical, unchanged from published severity.unchanged

Evidence used

  • CISA confirms exploitation in the wild.
  • A structured source references public exploit or proof-of-concept material.
  • The selected CVSS metric records a network-reachable, unauthenticated path with no user interaction.
  • EPSS is 99.64% for the current model date.

Compensating controls

  • Validate the affected product branch and deploy the verified fixed release.
  • Restrict the affected network interface to trusted sources where business-safe.
  • Increase monitoring for the attack path and post-exploitation behaviour described in the report.

Verification

  1. Confirm that the asset runs VMware Spring Framework and falls inside the recorded affected range.
  2. Verify the installed build against the product-specific fixed version after deployment.
  3. Validate exposure, authentication requirements and compensating controls in the actual environment.
  4. Reopen this reassessment when CVSS, KEV, EPSS, exploit evidence or remediation changes.
Mitigation target: Within 3 daysRemediation target: Within 90 days

This automated reassessment organises public evidence. It does not know asset exposure, business impact or control effectiveness and does not replace CVSS or a human risk decision.

Cross-source reconciliation

Remediation availability differs by product scope

Verified remediation exists for at least one product or source, but 11 structured product or package states remain unresolved. Apply remediation only to the exact product branch confirmed by its source.

Distribution package intelligence

Release-specific package status

Debian, ubuntu findings are scoped to the named distribution, release and source package. An absent finding does not mean a package is unaffected.

5 package states
Package result overrides the generic status

BlackTree has verified remediation for at least one product or source, but the relevant distribution still reports no fixed package for 4 affected package states shown here. Treat those rows as affected with no fix until that distribution publishes a fixed version.

Repository candidate not checked

A published vendor fix does not prove that a matching update is enabled and installable on a particular asset. Confirm the local package candidate before scheduling remediation.

Distribution releaseSource packageVendor stateFixed versionEvidence
Debian trixietrixie · sourcelibspring-javaAffected, no fix publishedDebian currently tracks this release as open.Not published in this feedDebian Security Tracker ↗Source updated 6 Oct 2026
Debian bookwormbookworm · sourcelibspring-javaAffected, no fix publishedDebian currently tracks this release as open.Not published in this feedDebian Security Tracker ↗Source updated 6 Oct 2026
Debian forkyforky · sourcelibspring-javaAffected, no fix publishedDebian currently tracks this release as open.Not published in this feedDebian Security Tracker ↗Source updated 6 Oct 2026
Debian sidsid · sourcelibspring-javaAffected, no fix publishedDebian currently tracks this release as open.Not published in this feedDebian Security Tracker ↗Source updated 6 Oct 2026
Ubuntu 24.04 LTSnoble · esm-appslibspring-javaVendor fix publishedCanonical reports that a fixed source package version has been published. Repository candidate availability is not checked by BlackTree.4.3.30-2ubuntu0.24.04.1~esm1Canonical Ubuntu Security ↗Source updated 5 Oct 2026
Open-source package ranges10 source-attributed ranges

These OSV and GitHub advisory ranges apply only to the named package and ecosystem. A listed fixed version is not a universal product patch or proof that an update is installed.

Ecosystem and packageAffected rangeFirst fixed versionEvidence
mavenorg.springframework.boot:spring-boot-starter-web< 2.5.122.5.12GitHub advisory ↗github reviewed aggregator · 22 Oct 2025
mavenorg.springframework.boot:spring-boot-starter-web>= 2.6.0, < 2.6.62.6.6GitHub advisory ↗github reviewed aggregator · 22 Oct 2025
mavenorg.springframework.boot:spring-boot-starter-webflux< 2.5.122.5.12GitHub advisory ↗github reviewed aggregator · 22 Oct 2025
mavenorg.springframework.boot:spring-boot-starter-webflux>= 2.6.0, < 2.6.62.6.6GitHub advisory ↗github reviewed aggregator · 22 Oct 2025
mavenorg.springframework:spring-beans>= 5.3.0, < 5.3.185.3.18GitHub advisory ↗github reviewed aggregator · 22 Oct 2025
mavenorg.springframework:spring-beans< 5.2.20.RELEASE5.2.20.RELEASEGitHub advisory ↗github reviewed aggregator · 22 Oct 2025
mavenorg.springframework:spring-webflux>= 5.3.0, < 5.3.185.3.18GitHub advisory ↗github reviewed aggregator · 22 Oct 2025
mavenorg.springframework:spring-webflux< 5.2.20.RELEASE5.2.20.RELEASEGitHub advisory ↗github reviewed aggregator · 22 Oct 2025
mavenorg.springframework:spring-webmvc>= 5.3.0, < 5.3.185.3.18GitHub advisory ↗github reviewed aggregator · 22 Oct 2025
mavenorg.springframework:spring-webmvc< 5.2.20.RELEASE5.2.20.RELEASEGitHub advisory ↗github reviewed aggregator · 22 Oct 2025
Direct vendor intelligence

Authoritative vendor CSAF and VEX advisories

Structured product status and remediation from the issuing vendor. Product-state explanations are always visible; large lists can be searched or downloaded.

2 current
CVE-2022-22965 · CSAF 2.0 · revision 3 · finalRed Hat Product Securityspring-framework: RCE via Data Binding on JDK 9+
4 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • spring-beans as a component of Red Hat Integration Camel Quarkus 1
  • spring-webmvc as a component of Red Hat JBoss A-MQ 6
  • spring-webmvc as a component of Red Hat JBoss Fuse 6
  • rhvm-dependencies.src as a component of Red Hat Virtualization 4
Summary
A flaw was found in Spring Framework, specifically within two modules called Spring MVC and Spring WebFlux, (transitively affected from Spring Beans), using parameter data binding. This flaw allows an attacker to pass specially-constructed malicious requests to certain parameters and possibly gain access to normally-restricted functionality within the Java Virtual Machine.
Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
SSA-254054 · CSAF 2.0 · revision 4 · finalSiemens ProductCERTSSA-254054: Spring Framework Vulnerability (Spring4Shell or SpringShell, CVE-2022-22965) - Impact to Siemens Products
7 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • Operation Scheduler
  • SIMATIC Speech Assistant for Machines (SAM)
  • SINEC NMS
  • SiPass integrated V2.80
  • SiPass integrated V2.85
  • Siveillance Identity V1.5
  • Siveillance Identity V1.6
Summary
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
Remediation
Apply the patch
Optional official sources

National CERT insights
?CERT means Computer Emergency Response Team; CSIRT is the closely related term Computer Security Incident Response Team.

Choose official national sources for this report. Each advisory shows its original language. Your selection is remembered on this device and included in shared links.

Official European source

ENISA European Vulnerability Database

Official EUVD identifiers, advisory evidence and known-exploited context. Missing fields are not treated as evidence of low risk.

1 current
ENISA EUVD identifier

EUVD-2022-1283

CISA KEV mirrored by ENISA

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

EUVD state
Present in the current official mapping
Known exploitation
Recorded by ENISA since 4 Apr 2022. Evidence sources: cisa_kev.
ENISA score
9.8 · CVSS 3.1
Advisory evidence
18 linked advisory records
Explicit mitigation evidence

Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.

  • csaf_redhat · RHSA-2022:1379Red Hat Security Advisory: Red Hat Decision Manager 7.12.1 security update
  • csaf_redhat · RHSA-2022:1306Red Hat Security Advisory: Red Hat Integration Camel Extensions for Quarkus 2.2.1-1 security update
  • csaf_redhat · RHSA-2022:1378Red Hat Security Advisory: Red Hat Process Automation Manager 7.12.1 security update
  • csaf_redhat · RHSA-2022:1626Red Hat Security Advisory: Red Hat AMQ Broker 7.8.6 release and security update
  • csaf_redhat · RHSA-2022:1360Red Hat Security Advisory: Red Hat Fuse 7.10.2 release and security update
  • csaf_redhat · RHSA-2022:1627Red Hat Security Advisory: Red Hat AMQ Broker 7.9.4 release and security update
  • csaf_redhat · RHSA-2022:1333Red Hat Security Advisory: Red Hat Integration Camel-K 1.6.5 security update
Recommended actionPatch only the product branches with a verified fix

CISA confirms exploitation in the wild and lists 2022-04-25 as the remediation due date. Verified remediation exists for at least one product or source, but 11 structured product or package states remain unresolved. Apply remediation only to the exact product branch confirmed by its source.

Fix availability varies by product
01

What, why and how

Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.

What

Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.

Why

Untrusted data can cross into a code-evaluation path and be interpreted as executable instructions.

How

An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may execute code or commands in the affected security context.

What

Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.

Why

Untrusted data can cross into a code-evaluation path and be interpreted as executable instructions.

How

An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may execute code or commands in the affected security context.

02

Exploit reality and attack path

CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.

Observed exploitation
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
Confirmed in the wild

CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2022-04-04.

Public PoC / exploit material
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
Reference recorded

A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.

Likely attack path
a network path → Improper Control of Generation of Code ('Code Injection') → execute code or commands in the affected security context
Attack surface
Network
Privileges required
None: unauthenticated exploitation is possible
User interaction
None
Attack complexity
Low: no specialised conditions are recorded
Security boundary
Unchanged: impact remains within the vulnerable component's security authority
Weakness
?CWE means Common Weakness Enumeration: a standard category for the underlying weakness.
CWE-94 ↗

CWE-94: Improper Control of Generation of Code ('Code Injection'). The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

CVSS vector
?CVSS means Common Vulnerability Scoring System. The vector records the metric values used to calculate technical severity.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Common Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.

AVNetworkAttack vector: The vulnerable component can be reached over a network.ACLowAttack complexity: No specialised conditions are required beyond attacker-controlled input.PRNonePrivileges required: The attacker does not need an account or existing privileges.UINoneUser interaction: No action by another user is required.SUnchangedScope: The security impact remains within the vulnerable component's authority.CHighConfidentiality impact: A successful attack can cause a major loss.IHighIntegrity impact: A successful attack can cause a major loss.AHighAvailability impact: A successful attack can cause a major loss.
Post-exploitation / living off the land
After compromise, an attacker may use built-in shells, scripting engines, scheduled tasks and native network utilities for discovery, persistence or movement. This is a plausible LoTL path, not evidence that it has occurred for every attack.
NetworkUnauthenticatedRemote code executionCWE-94CISA KEVPublic exploit reference
A

Official authority intelligence

Only matched European and national findings are included. Language selectors and unavailable sources are omitted.

ENISA EUVD · EUVD-2022-1283Known-exploited evidence recorded

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

Official EUVD record ↗
BSI · German · WID-SEC-2022-0033VMware Tanzu Spring Framework: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in VMware Tanzu Spring Framework ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen.

Official advisory ↗
BSI · German · WID-SEC-2026-1955Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.

Official advisory ↗
BSI · German · WID-SEC-2024-0528Dell Data Protection Advisor: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand herbeizuführen, Dateien zu manipulieren, vertrauliche Informationen offenzulegen, seine Berechtigungen zu erweitern oder einen nicht spezifizierten Angriff durchzuführen.

Official advisory ↗
BSI · German · WID-SEC-2023-1016Oracle Fusion Middleware: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2023-1012Oracle Insurance Applications: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Insurance Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2023-0139Oracle Commerce: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Commerce ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2023-0016IBM Tivoli Monitoring: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Tivoli Monitoring ausnutzen, um die Kontrolle über das System zu erlangen, vertrauliche Informationen offenzulegen, einen Denial of Service Zustand herbeizuführen, sowie weitere nicht spezifizierte Auswirkungen zu ereichen.

Official advisory ↗
BSI · German · WID-SEC-2022-0169Oracle MySQL: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle MySQL ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
Cyber Security Agency of Singapore · English · CSA-SB-20220406Security Bulletin 06 Apr 2022

The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 06 Apr 2022, published on 6 April 2022. Open the linked bulletin for the product, severity and reference information published in that issue.

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0756Multiples vulnérabilités dans les produits VMware

d?id=CVE-2022-21553 Référence CVE CVE-2022-21556 https://www.cve.org/CVERecord?id=CVE-2022-21556 Référence CVE CVE-2022-21569 https://www.cve.org/CVERecord?id=CVE-2022-21569 Référence CVE CVE-2022-21589 https://www.cve.org/CVERecord?id=CVE-2022-21589 Référence CVE CVE-2022-21592 https://www.cve.org/CVERecord?id=CVE-2022-21592 Référence CVE CVE-2022-21595 https://www.cve.org/CVERecord?id=CVE-2022-21595 Référence CVE CVE-2022-21608 https://www.cve.org/CVERecord?id=CVE-2022-21608 Référence CVE CVE-2022-21617 https://www.cve.org/CVERecord?id=CVE-2022-21617 Référence CVE CVE-2022-22942 https://www.cve.org/CVERecord?id=CVE-2022-22942 Référence CVE CVE-2022-22965 https://www.cve.org/CVERecord?id=CVE-2022-22965 Référence CVE CVE-2022-2309 https://www.cve.org/CVERecord?id=CVE-2022-2309 Référence CVE CVE-2022-23218 https://www.cve.org/CVERecord?id=CVE-2022-23218 Référence CVE CVE-2022-23219 https://www.cve.org/CVERecord?id=CVE-2022-23219 Référence CVE CVE-2022-25883 https://www.cve.org/CVERecord?id=CVE-2022-25883 Référence CVE CVE-2022-27772 https://www.cve.org/CVERecord?id=CVE-2022-27772 Référence CVE CVE-2022-27782 https://www.cve.org/CVERecord?id=CVE-2022-27782 Référence CVE CVE-2022-2795 https://www.cve.org/CVERecord?id=CVE-2022-2795 Référence CVE CVE-2022-28321 https://www.cve.org/CVERecord?id=CVE-

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-928Multiples vulnérabilités dans les produits IBM

g/CVERecord?id=CVE-2021-37713 Référence CVE CVE-2021-3807 https://www.cve.org/CVERecord?id=CVE-2021-3807 Référence CVE CVE-2021-3918 https://www.cve.org/CVERecord?id=CVE-2021-3918 Référence CVE CVE-2021-4160 https://www.cve.org/CVERecord?id=CVE-2021-4160 Référence CVE CVE-2021-4189 https://www.cve.org/CVERecord?id=CVE-2021-4189 Référence CVE CVE-2021-43138 https://www.cve.org/CVERecord?id=CVE-2021-43138 Référence CVE CVE-2021-44906 https://www.cve.org/CVERecord?id=CVE-2021-44906 Référence CVE CVE-2021-44907 https://www.cve.org/CVERecord?id=CVE-2021-44907 Référence CVE CVE-2022-0391 https://www.cve.org/CVERecord?id=CVE-2022-0391 Référence CVE CVE-2022-22965 https://www.cve.org/CVERecord?id=CVE-2022-22965 Référence CVE CVE-2022-24758 https://www.cve.org/CVERecord?id=CVE-2022-24758 Référence CVE CVE-2022-25647 https://www.cve.org/CVERecord?id=CVE-2022-25647 Référence CVE CVE-2022-26488 https://www.cve.org/CVERecord?id=CVE-2022-26488 Référence CVE CVE-2022-34339 https://www.cve.org/CVERecord?id=CVE-2022-34339 Gestion détaillée du document le 19 octobre 2022 Version initiale Alertes Avis Bulletins d’actualités Mentions légales Conditions générales À propos Contact cyber.gouv.fr service-public.fr legifrance.gouv.fr info.gouv.fr france.fr info.gouv.fr/risques Premier Ministre / Secrétariat Général de

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-716Multiples vulnérabilités dans IBM Cloud Pak System

De multiples vulnérabilités ont été découvertes dans IBM Cloud Pak System. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et un contournement de la politique de sécurité.

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-659Multiples vulnérabilités dans Oracle WebLogic

De multiples vulnérabilités ont été découvertes dans Oracle WebLogic. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, un déni de service à distance et une atteinte à l'intégrité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-626Multiples vulnérabilités dans IBM i Modernization

De multiples vulnérabilités ont été découvertes dans IBM i Modernization. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-572Vulnérabilité dans les produits IBM

Une vulnérabilité a été découverte dans les produits IBM. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-568Multiples vulnérabilités dans les produits IBM

alytics for Communications Service Providers and Datasets (CNA) versions 10.0.0.x antérieures à 10.0.0.2 IBM Disconnected Log Collector versions 1.x antérieures à 1.7.3 IBM QRadar SIEM versions 7.3 sans le correctif de sécurité 7.3.0-QRADAR-PROTOCOL-ApacheKafka-7.3-20220429171209 IBM QRadar SIEM versions 7.4 sans le correctif de sécurité 7.4.0-QRADAR-PROTOCOL-ApacheKafka-7.4-20220429171217 IBM QRadar SIEM versions 7.5 sans le correctif de sécurité 7.5.0-QRADAR-PROTOCOL-ApacheKafka-7.5-20220429171113 IBM Rational Test Control Panel component in Rational Test Virtualization Server toutes versions sans le correctif de sécurité Rational-RTCP- - -CVE-2022-22965-ifix IBM Rational Test Control Panel component in Rational Test Workbench toutes versions sans le correctif de sécurité Rational-RTCP- - -CVE-2022-22965-ifix Résumé De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité. Solution Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation). Documentation Bulletin de sécurité les produits IBM 6595721 du 16 juin 2022 https://www.ibm.com/support/page

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-539Multiples vulnérabilités dans IBM DB2

De multiples vulnérabilités ont été découvertes dans IBM DB2. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-523Multiples vulnérabilités dans les produits IBM

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-494Multiples vulnérabilités dans les produits IBM

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-487Multiples vulnérabilités dans les produits IBM

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service et un contournement de la politique de sécurité.

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-481Multiples vulnérabilités dans les produits IBM

De multiples vulnérabilités ont été découvertes dans les produits IBM. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-472Multiples vulnérabilités dans les produits IBM

De multiples vulnérabilités ont été découvertes dans les produits IBM. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et un déni de service à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-456Multiples vulnérabilités dans les produits SAP

De multiples vulnérabilités ont été découvertes dans les produits SAP. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un contournement de la politique de sécurité et une atteinte à l'intégrité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-376Multiples vulnérabilités dans Fortinet FortiSOAR

De multiples vulnérabilités ont été découvertes dans Fortinet FortiSOAR. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-371Multiples vulnérabilités dans les produits Cisco

De multiples vulnérabilités ont été découvertes dans les produits Cisco. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un contournement de la politique de sécurité et une atteinte à l'intégrité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-360Vulnérabilité dans les produits Siemens

Une vulnérabilité a été découverte dans les produits Siemens. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-345Multiples vulnérabilités dans les produits SAP

ord?id=CVE-2021-44832 Référence CVE CVE-2022-0613 https://www.cve.org/CVERecord?id=CVE-2022-0613 Référence CVE CVE-2022-22532 https://www.cve.org/CVERecord?id=CVE-2022-22532 Référence CVE CVE-2022-22533 https://www.cve.org/CVERecord?id=CVE-2022-22533 Référence CVE CVE-2022-22536 https://www.cve.org/CVERecord?id=CVE-2022-22536 Référence CVE CVE-2022-22541 https://www.cve.org/CVERecord?id=CVE-2022-22541 Référence CVE CVE-2022-22542 https://www.cve.org/CVERecord?id=CVE-2022-22542 Référence CVE CVE-2022-22543 https://www.cve.org/CVERecord?id=CVE-2022-22543 Référence CVE CVE-2022-22545 https://www.cve.org/CVERecord?id=CVE-2022-22545 Référence CVE CVE-2022-22965 https://www.cve.org/CVERecord?id=CVE-2022-22965 Référence CVE CVE-2022-23181 https://www.cve.org/CVERecord?id=CVE-2022-23181 Référence CVE CVE-2022-26101 https://www.cve.org/CVERecord?id=CVE-2022-26101 Référence CVE CVE-2022-26105 https://www.cve.org/CVERecord?id=CVE-2022-26105 Référence CVE CVE-2022-26106 https://www.cve.org/CVERecord?id=CVE-2022-26106 Référence CVE CVE-2022-26107 https://www.cve.org/CVERecord?id=CVE-2022-26107 Référence CVE CVE-2022-26108 https://www.cve.org/CVERecord?id=CVE-2022-26108 Référence CVE CVE-2022-26109 https://www.cve.org/CVERecord?id=CVE-2022-26109 Référence CVE CVE-2022-27654 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-326Multiples vulnérabilités dans les produits SolarWinds

De multiples vulnérabilités ont été découvertes dans les produits SolarWinds. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-307Vulnérabilité dans VMware Tanzu

Une vulnérabilité a été découverte dans VMware Tanzu. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-297Vulnérabilité dans VMware Spring

Une vulnérabilité a été découverte dans VMware Spring. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2022-001498Spring Framework における不適切なデータバインディング処理による任意コード実行の脆弱性

Spring Framework は、Java 言語で Web アプリケーションなどを作成するために用いられるフレームワークです。Spring Framework には、データバインディングで使用する、CachedIntrospectionResults クラス内の PropertyDescriptor オブジェクトを安全に処理しない脆弱性(CVE-2022-22965)があります。その結果、攻撃者により class.classLoader を呼び出され、システム内で任意の Java コードが実行される可能性があります。 2010年に同種の脆弱性が CVE-2010-1622 として報告され、Spring Framework 2.5.6.SEC02 において修正されました。今回報告された CVE-2022-22965 はこの修正を回避する新たな攻撃手法を提供するものです。 なお、VMWare によると本脆弱性を悪用する攻撃を成功させるためには複数の条件が必要であることが示唆されています。2022年4月1日現在、同社が報告を受けた攻撃シナリオにおいては、以下の条件が必要であったとのことです。  * JDK 9 以上を使用している  * Apache Tomcat をサーブレットコンテナとして使用している  * WAR 形式でデプロイされている  * プログラムが spring-webmvc あるいは spring-webflux に依存している ただし、上記以外にも攻撃が成功するための条件が存在する可能性があります。今後公開される情報を注視してください。

Official advisory ↗
KISA KrCERT/CC · Korean · KNVD-5873최근 해킹 공격에 활용되는 취약점 보안 업데이트 권고

(CVE-2021-44228)[9] ㅇ Atlassian Confluence Server 및 Data Center에서 OGNL 인젝션으로 인해 발생하는 원격코드실행 취약점(CVE-2021-26084)[10] ㅇ BIG-IP에서 iControl REST 인증 미흡으로 인해 발생하는 불충분한 인가 취약점(CVE-2022-1388)[11] ㅇ BIG-IP, BIG-IQ의 iControl REST 인터페이스에서 발생하는 원격 코드 실행 취약점(CVE-2021-22986)[12] ㅇ Grafana 소프트웨어에서 경로탐색(Directory Traversal)으로 인해 발생하는 정보노출 취약점(CVE-2021-43798)[13] ㅇ Inspur ClusterEngine V4.0에서 발생하는 원격 코드 실행 취약점(CVE-2020-21224)[14] ㅇ Oracle WebLogic Server에서 발생하는 원격 코드 실행 취약점(CVE-2021-2109)[15] ㅇ SMBv3 프로토콜이 조작된 패킷을 처리할 때 버퍼오버플로우로 인해 발생하는 원격코드실행 취약점(CVE-2020-0796)[16] ㅇ Spring Cloud Gateway에서 발생하는 원격코드 실행 취약점(CVE-2022-22947)[17] ㅇ Spring Core에서 발생하는 원격코드실행 취약점(CVE-2022-22965)[18] ㅇ Spring Cloud Function에서 발생하는 원격코드실행 취약점(CVE-2022-22963)[18] ㅇ VMware vCenter Server 원격 코드 실행 취약점(CVE-2021-21972)[19] ㅇ VMware vCenter Server 에서 발생하는 파일 업로드 취약점(CVE-2021-22005)[20] ㅇ VMware Workspace ONE Access와 Identity Manager에서 발생하는 원격 코드 실행 취약점(CVE-2022-22954)[21] ㅇ WebLogic Server에서 안전하지 않은 역직렬화로 인해 발생하는 인증 우회 및 원격코드 실행 취약점(CVE-2019-2725)[22] ㅇ WSO2에서 발생하는 원격코드 실행 취약점(CVE-2022-29464)[23] ##### □ 해결 방안 o 취약점별 참고사이트[1]~[23]에 명시되어 있는 내용을 참조하여 업데이트 수행 ##### □ 기타 문의사항 o 한국인터넷진흥원 사이버민원센터: 국번없이 118 [참고사이트] [1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45232 [2] https://boho.or.kr/data/secNoticeView.do?bulletin_writing_seque

Official advisory ↗
KISA KrCERT/CC · Korean · KNVD-5559Spring Java 프레임워크 보안 업데이트 권고(CVE-2022-22965, CVE-2022-22963) (Update. 22-4-6 15:00)

#### Spring Java 프레임워크 보안 업데이트 권고(CVE-2022-22965, CVE-2022-22963) (Update. 22-4-6 15:00) 2022.03.31 2022-3-31 : Spring4Shell, CVE-2022-22963 취약점 보안 업데이트 2022-4-1 : CVE-2022-22965(Spring4Shell) 취약점 보안 업데이트 추가 2022-4-6 : 제조사별 현황 추가 ##### □ 개요 o Spring 보안팀에서 Spring 프레임워크 및 Spring Cloud Function 관련 원격코드 실행 취약점을 해결한 임시조치 방안 및 보안업데이트 권고 o 공격자는 해당 취약점을 이용하여 정상 서비스에 피해를 발생시킬 수 있으므로, 최신 버전으로 업데이트 권고 ※ 참고 사이트[5]를 확인하여 해당 제품을 이용 중일 경우, 해당 제조사의 권고에 따라 패치 또는 대응 방안 적용 ##### □ 주요 내용 o Spring Core에서 발생하는 원격코드실행 취약점( CVE-2022-22965 )[1] o Spring Cloud Function에서 발생하는 원격코드실행 취약점 (CVE-2022-22963)[2] ##### □ 영향을 받는 버전 o CVE-2022-22965 (Spring4Shell) - 1) JDK 9 이상의 2) Spring 프레임워크 사용하는 경우 - Spring Framework 5.

Official advisory ↗
03

Patch and workaround

Operational remediation based on structured source evidence.

Status
?Patch availability is based on structured fixed-version fields and authoritative update references. If no fix is verified, check the vendor advisory before making a change.
Fix availability varies by product
Affected
Fixed
Action
Use the product-specific evidence above. Patch only products with a verified fixed release, and keep every affected or under-investigation state without a matching fix in the remediation queue.
Workaround
A mitigation or workaround reference is available from the source linked below; validate it against the affected product and version.
04

Evidence and provenance

Published 1 Apr 2022 · Last source change 21 Oct 2025, 23:15 UTC · CWE-94 · Improper Control of Generation of Code ('Code Injection')

CVE recordCVE.org · 5.1
CVSS sourceNIST NVD
EPSS source
?The date BlackTree first stored a score for this CVE from the daily FIRST EPSS feed.
FIRST · tracked since 2026-08-14
European sourceENISA EUVD · EUVD-2022-1283
Product sourceVendor CSAF · Red Hat Product Security
Remediation sourceVendor CSAF · Red Hat Product Security
CWE sourceCNA
NVD statusNVD enriched

Core structured fields are present and their contributing authorities are shown above.

Material change intelligence

What changed after publication

View recent updates ↗
  1. Affected versionsThe structured affected or fixed version information changed.
    Before
    Spring Framework: Spring Framework versions 5.3.X prior to 5.3.18+, 5.2.x prior to 5.2.20+ and all old and unsupported versions · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    After
    Spring Framework: Spring Framework versions 5.3.X prior to 5.3.18+, 5.2.x prior to 5.2.20+ and all old and unsupported versions · Fixed: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
    Red Hat Product Security ↗
  2. Affected versionsThe structured affected or fixed version information changed.
    Before
    Spring Framework: Spring Framework versions 5.3.X prior to 5.3.18+, 5.2.x prior to 5.2.20+ and all old and unsupported versions · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    After
    Spring Framework: Spring Framework versions 5.3.X prior to 5.3.18+, 5.2.x prior to 5.2.20+ and all old and unsupported versions · Fixed: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
    Red Hat Product Security ↗
  3. Vendor guidanceAuthoritative vendor guidance changed: added remediation: cert-portal.siemens.com/ssa-254054.pdf; removed remediation: access.redhat.com/CVE-2022-22965.
    Before
    mitigation: tanzu.vmware.com/cve-2022-22965 · patch: cert-portal.siemens.com/ssa-254054.pdf · patch: oracle.com/cpujul2022.html · 1 more references
    After
    mitigation: tanzu.vmware.com/cve-2022-22965 · patch: cert-portal.siemens.com/ssa-254054.pdf · patch: oracle.com/cpujul2022.html · 1 more references
    cert-portal.siemens.com ↗
  4. Affected versionsThe structured affected or fixed version information changed.
    Before
    Spring Framework: Spring Framework versions 5.3.X prior to 5.3.18+, 5.2.x prior to 5.2.20+ and all old and unsupported versions · Fixed: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
    After
    Spring Framework: Spring Framework versions 5.3.X prior to 5.3.18+, 5.2.x prior to 5.2.20+ and all old and unsupported versions · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    CISA KEV ↗
  5. Affected versionsThe structured affected or fixed version information changed.
    Before
    Spring Framework versions 5.3.X prior to 5.3.18+, 5.2.x prior to 5.2.20+ and all old and unsupported versions · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    After
    Spring Framework: Spring Framework versions 5.3.X prior to 5.3.18+, 5.2.x prior to 5.2.20+ and all old and unsupported versions · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    CNA ↗
Material fields only · duplicate refreshes suppressed · history retained for the configured operational retention period
Technical terms and abbreviations used in this report
CVE
Common Vulnerabilities and Exposures: the public identifier for one disclosed vulnerability.
CVSS
Common Vulnerability Scoring System: a technical severity framework; it is not patching priority by itself.
EPSS
Exploit Prediction Scoring System: FIRST's estimate of the probability that exploitation activity will be observed in the next 30 days; it is a forecast, not confirmation.
CWE
Common Weakness Enumeration: the standard category describing the underlying software or hardware weakness.
CNA
CVE Numbering Authority: an organisation authorised to assign and publish CVE records.
CISA ADP
Cybersecurity and Infrastructure Security Agency Authorized Data Publisher: structured enrichment added to a CVE record.
NVD
National Vulnerability Database: NIST's enrichment service for CVE records.
CERT / CSIRT
A computer security incident response team that publishes warnings or coordinates incident response.
PoC
Proof of concept: public material that demonstrates or helps reproduce exploitation.
CSAF
Common Security Advisory Framework: a machine-readable format for security advisories.
LoTL
Living off the land: abuse of legitimate tools or system functions during an attack.
Free version - for non-commercial use only.CVE-2022-22965 · cve.blacktree.nl