SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2022-22965

Spring Framework JDK 9+ Remote Code Execution Vulnerability

KEVCRITICAL 9.8EPSS 99.6%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 25 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
99.64% probability · 100th percentile
CISA KEV
Listed 4 April 2022 · due 25 April 2022
Weakness
CWE-94
Affected
vmware/spring framework · cisco/cx cloud agent · oracle/communications cloud native core automated test suite · oracle/communications cloud native core console · oracle/communications cloud native core network exposure function · oracle/communications cloud native core network function cloud native environment · oracle/communications cloud native core network repository function · oracle/communications cloud native core network slice selection function · oracle/communications cloud native core policy · oracle/communications cloud native core security edge protection proxy · oracle/communications cloud native core unified data repository · oracle/communications policy management · oracle/financial services analytical applications infrastructure · oracle/financial services behavior detection platform · oracle/financial services enterprise case management · oracle/mysql enterprise monitor · oracle/product lifecycle analytics · oracle/retail xstore point of service · oracle/sd-wan edge · siemens/operation scheduler · +18 more
Source
security@vmware.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2022-22965

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.