PromptRiskDBThreat intelligence atlas

CVE-2022-22965 - VMware Spring Framework

AI Vulnerability Context

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways...

Overview

A source-backed snapshot of this vulnerability.

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

CISA KEVyesWhether CISA lists this as exploited.
Techniques0AI attack methods connected to this vulnerability.
Case studies0Examples where this vulnerability is mentioned.

Vulnerability status

How serious this vulnerability is and whether it is known to be exploited.

CISA KEVCRITICAL
CVE ID
CVE-2022-22965
Vendor/project
VMware
Product
Spring Framework
Vulnerability name
Spring Framework JDK 9+ Remote Code Execution Vulnerability
Date added
2022-04-04
Due date
2022-04-25
Known ransomware campaign use
Unknown
CVSS v3
9.8
CWE-94

Exploit context

What the vulnerability is about.

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

Source evidence

Original public records and references for this page.

Original source

Original source links

Open the public records and source datasets used for this page.