CVE-2022-22963
VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 September 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 99.94% probability · 100th percentile
- CISA KEV
- Listed 25 August 2022 · due 15 September 2022
- Weakness
- CWE-94, CWE-917
- Affected
- vmware/spring cloud function · oracle/banking branch · oracle/banking cash management · oracle/banking corporate lending process management · oracle/banking credit facilities process management · oracle/banking electronic data exchange for corporates · oracle/banking liquidity management · oracle/banking origination · oracle/banking supply chain finance · oracle/banking trade finance process management · oracle/banking virtual account management · oracle/communications cloud native core automated test suite · oracle/communications cloud native core console · oracle/communications cloud native core network exposure function · oracle/communications cloud native core network function cloud native environment · oracle/communications cloud native core network repository function · oracle/communications cloud native core network slice selection function · oracle/communications cloud native core policy · oracle/communications cloud native core security edge protection proxy · oracle/communications cloud native core unified data repository · +8 more
- Source
- security@vmware.com
CISA notes
Apply updates per vendor instructions. https://tanzu.vmware.com/security/cve-2022-22963; https://nvd.nist.gov/vuln/detail/CVE-2022-22963
References
- http://packetstormsecurity.com/files/173430/Spring-Cloud-3.2.2-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005Third Party Advisory
- https://tanzu.vmware.com/security/cve-2022-22963Vendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-scf-rce-DQrHhJxHThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
- http://packetstormsecurity.com/files/173430/Spring-Cloud-3.2.2-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005Third Party Advisory
- https://tanzu.vmware.com/security/cve-2022-22963Vendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-scf-rce-DQrHhJxHThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22963US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.