CVE-2022-22965
Unknown
Unknown - Not Provided
BaseFortify
Vulnerability report for CVE-2022-22965, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2022-04-01
Last updated on: 2025-10-30
Assigner: VMware
Description
Description
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| vmware | spring_framework | to 5.2.20 (exc) |
| vmware | spring_framework | From 5.3.0 (inc) to 5.3.18 (exc) |
| oracle | jdk | From 9 (inc) |
| cisco | cx_cloud_agent | to 2.1.0 (exc) |
| oracle | communications_cloud_native_core_automated_test_suite | 1.9.0 |
| oracle | communications_cloud_native_core_automated_test_suite | 22.1.0 |
| oracle | communications_cloud_native_core_console | 1.9.0 |
| oracle | communications_cloud_native_core_console | 22.1.0 |
| oracle | communications_cloud_native_core_network_exposure_function | 22.1.0 |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | 1.10.0 |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | 22.1.0 |
| oracle | communications_cloud_native_core_network_repository_function | 1.15.0 |
| oracle | communications_cloud_native_core_network_repository_function | 22.1.0 |
| oracle | communications_cloud_native_core_network_slice_selection_function | 1.8.0 |
| oracle | communications_cloud_native_core_network_slice_selection_function | 1.15.0 |
| oracle | communications_cloud_native_core_network_slice_selection_function | 22.1.0 |
| oracle | communications_cloud_native_core_policy | 1.15.0 |
| oracle | communications_cloud_native_core_policy | 22.1.0 |
| oracle | communications_cloud_native_core_security_edge_protection_proxy | 1.7.0 |
| oracle | communications_cloud_native_core_security_edge_protection_proxy | 22.1.0 |
| oracle | communications_cloud_native_core_unified_data_repository | 1.15.0 |
| oracle | communications_cloud_native_core_unified_data_repository | 22.1.0 |
| oracle | communications_policy_management | 12.6.0.0.0 |
| oracle | financial_services_analytical_applications_infrastructure | 8.1.1 |
| oracle | financial_services_analytical_applications_infrastructure | 8.1.2.0 |
| oracle | financial_services_behavior_detection_platform | 8.1.1.0 |
| oracle | financial_services_behavior_detection_platform | 8.1.1.1 |
| oracle | financial_services_behavior_detection_platform | 8.1.2.0 |
| oracle | financial_services_enterprise_case_management | 8.1.1.0 |
| oracle | financial_services_enterprise_case_management | 8.1.1.1 |
| oracle | financial_services_enterprise_case_management | 8.1.2.0 |
| oracle | mysql_enterprise_monitor | to 8.0.29 (exc) |
| oracle | product_lifecycle_analytics | 3.6.1 |
| oracle | retail_xstore_point_of_service | 20.0.1 |
| oracle | retail_xstore_point_of_service | 21.0.0 |
| oracle | sd-wan_edge | 9.0 |
| oracle | sd-wan_edge | 9.1 |
| siemens | operation_scheduler | to 2.0.4 (exc) |
| siemens | sipass_integrated | 2.80 |
| siemens | sipass_integrated | 2.85 |
| siemens | siveillance_identity | 1.5 |
| siemens | siveillance_identity | 1.6 |
| veritas | access_appliance | 7.4.3 |
| veritas | access_appliance | 7.4.3.100 |
| veritas | access_appliance | 7.4.3.200 |
| veritas | access_appliance | 7.4.3 |
| veritas | access_appliance | 7.4.3.100 |
| veritas | access_appliance | 7.4.3.200 |
| veritas | flex_appliance | 1.3 |
| veritas | flex_appliance | 2.0 |
| veritas | flex_appliance | 2.0.1 |
| veritas | flex_appliance | 2.0.2 |
| veritas | flex_appliance | 2.1 |
| veritas | netbackup_flex_scale_appliance | 2.1 |
| veritas | netbackup_flex_scale_appliance | 3.0 |
| veritas | netbackup_appliance | 4.0 |
| veritas | netbackup_appliance | 4.0.0.1 |
| veritas | netbackup_appliance | 4.0.0.1 |
| veritas | netbackup_appliance | 4.0.0.1 |
| veritas | netbackup_appliance | 4.1 |
| veritas | netbackup_appliance | 4.1.0.1 |
| veritas | netbackup_appliance | 4.1.0.1 |
| veritas | netbackup_virtual_appliance | 4.0 |
| veritas | netbackup_virtual_appliance | 4.0.0.1 |
| veritas | netbackup_virtual_appliance | 4.0.0.1 |
| veritas | netbackup_virtual_appliance | 4.0.0.1 |
| veritas | netbackup_virtual_appliance | 4.1 |
| veritas | netbackup_virtual_appliance | 4.1.0.1 |
| veritas | netbackup_virtual_appliance | 4.1.0.1 |
| siemens | operation_scheduler | to 2.0.4 (exc) |
| siemens | simatic_speech_assistant_for_machines | to 1.2.1 (exc) |
| siemens | sinec_network_management_system | to 1.0.3 (exc) |
| siemens | sipass_integrated | 2.80 |
| siemens | sipass_integrated | 2.85 |
| siemens | siveillance_identity | 1.5 |
| siemens | siveillance_identity | 1.6 |
| oracle | commerce_platform | 11.3.2 |
| oracle | communications_cloud_native_core_binding_support_function | 22.1.3 |
| oracle | communications_unified_inventory_management | 7.4.1 |
| oracle | communications_unified_inventory_management | 7.4.2 |
| oracle | communications_unified_inventory_management | 7.5.0 |
| oracle | retail_bulk_data_integration | 16.0.3 |
| oracle | retail_customer_management_and_segmentation_foundation | 17.0 |
| oracle | retail_customer_management_and_segmentation_foundation | 18.0 |
| oracle | retail_customer_management_and_segmentation_foundation | 19.0 |
| oracle | retail_financial_integration | 14.1.3.2 |
| oracle | retail_financial_integration | 15.0.3.1 |
| oracle | retail_financial_integration | 16.0.3 |
| oracle | retail_financial_integration | 19.0.1 |
| oracle | retail_integration_bus | 14.1.3.2 |
| oracle | retail_integration_bus | 15.0.3.1 |
| oracle | retail_integration_bus | 16.0.3 |
| oracle | retail_integration_bus | 19.0.1 |
| oracle | retail_merchandising_system | 16.0.3 |
| oracle | retail_merchandising_system | 19.0.1 |
| oracle | weblogic_server | 12.2.1.3.0 |
| oracle | weblogic_server | 12.2.1.4.0 |
| oracle | weblogic_server | 14.1.1.0.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-94 | The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment. |