Junglewise Threat Intelligence

CVE-2022-22947: Spring Cloud Gateway vulnerable to Code Injection when Gateway Actuator endpoint enabled, exposed, unsecured

CVE-2022-22947 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2022-03-04

Technologies: Oracle Commerce Guided Search, VMware Spring Cloud Gateway. Vendors: Oracle, VMware.

Executive brief

Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed, and unsecured. A remote attacker can send a maliciously crafted request to achieve arbitrary remote code execution on the host.

Affected products

  • VMware Spring Cloud Gateway prior to 3.1.1+ and 3.0.7+
  • Oracle Commerce Guided Search 11.3.2
  • Oracle Communications Cloud Native Core Binding Support Function 1.11.0, 22.1.3

Timeline

  • 2022-05-16: disclosed
  • 2022-05-16: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-01: other: Exploit code published on Packet Storm

Related threats