Junglewise Threat Intelligence

CVE-2022-22965: Remote Code Execution in Spring Framework

CVE-2022-22965 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2022-03-31

Technologies: VMware Spring Framework, Oracle Jdk. Vendors: VMware, Oracle.

Executive brief

A remote code execution vulnerability exists in Spring MVC and Spring WebFlux applications running on JDK 9+ due to improper data binding. Exploitation typically requires the application to be deployed as a WAR on Apache Tomcat, though the underlying vulnerability is more general. This flaw allows an unauthenticated attacker to execute arbitrary code on the host.

Affected products

  • VMware Spring Framework < 5.2.20, 5.3.0 to < 5.3.18
  • Oracle JDK >= 9

Timeline

  • 2022-04-04: disclosed
  • 2022-04-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-04-04: advisory: NVD publication date

Related threats