Executive brief
A remote code execution vulnerability exists in Spring MVC and Spring WebFlux applications running on JDK 9+ due to improper data binding. Exploitation typically requires the application to be deployed as a WAR on Apache Tomcat, though the underlying vulnerability is more general. This flaw allows an unauthenticated attacker to execute arbitrary code on the host.
Affected products
- VMware Spring Framework < 5.2.20, 5.3.0 to < 5.3.18
- Oracle JDK >= 9
Timeline
- 2022-04-04: disclosed
- 2022-04-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-04-04: advisory: NVD publication date