CVE-2022-22965
Spring Framework JDK 9+ Remote Code Execution Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 25 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 99.64% probability · 100th percentile
- CISA KEV
- Listed 4 April 2022 · due 25 April 2022
- Weakness
- CWE-94
- Affected
- vmware/spring framework · cisco/cx cloud agent · oracle/communications cloud native core automated test suite · oracle/communications cloud native core console · oracle/communications cloud native core network exposure function · oracle/communications cloud native core network function cloud native environment · oracle/communications cloud native core network repository function · oracle/communications cloud native core network slice selection function · oracle/communications cloud native core policy · oracle/communications cloud native core security edge protection proxy · oracle/communications cloud native core unified data repository · oracle/communications policy management · oracle/financial services analytical applications infrastructure · oracle/financial services behavior detection platform · oracle/financial services enterprise case management · oracle/mysql enterprise monitor · oracle/product lifecycle analytics · oracle/retail xstore point of service · oracle/sd-wan edge · siemens/operation scheduler · +18 more
- Source
- security@vmware.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2022-22965
References
- http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/167011/Spring4Shell-Spring-Framework-Class-Property-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- https://cert-portal.siemens.com/productcert/pdf/ssa-254054.pdfPatch, Third Party Advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005Third Party Advisory
- https://tanzu.vmware.com/security/cve-2022-22965Mitigation, Vendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
- http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/167011/Spring4Shell-Spring-Framework-Class-Property-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- https://cert-portal.siemens.com/productcert/pdf/ssa-254054.pdfPatch, Third Party Advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005Third Party Advisory
- https://tanzu.vmware.com/security/cve-2022-22965Mitigation, Vendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67Third Party Advisory
- https://www.kb.cert.org/vuls/id/970766US Government Resource
- https://www.oracle.com/security-alerts/cpuapr2022.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22965US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.