Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2022-22965: Spring Framework apps on Java 9+ could run attacker code

CVE-2022-22965 · published 4 days ago · actively exploited
Summary

Web applications built with Spring MVC or Spring WebFlux that run on Java 9 or newer may allow an attacker to execute their own code through crafted data. This could let the attacker take control of the server or access sensitive information. Update the Spring libraries to the latest patched versions and ensure you are using a supported Java runtime.

What to do
  • Update springframework org.springframework:spring-beans to version 5.3.18.
  • Update springframework org.springframework:spring-webmvc to version 5.3.18.
  • Update springframework org.springframework.boot:spring-boot-starter-web to version 2.5.12.
  • Update springframework org.springframework.boot:spring-boot-starter-web to version 2.6.6.
  • Update springframework org.springframework:spring-webflux to version 5.3.18.
  • Update springframework org.springframework.boot:spring-boot-starter-webflux to version 2.5.12.
  • Update springframework org.springframework.boot:spring-boot-starter-webflux to version 2.6.6.
  • Update springframework org.springframework:spring-beans to version 5.2.20.RELEASE.
  • Update springframework org.springframework:spring-webmvc to version 5.2.20.RELEASE.
  • Update springframework org.springframework:spring-webflux to version 5.2.20.RELEASE.
  • Update org.springframework:spring-beans to version 5.3.14-aikido.2.
  • Update io.root.org.springframework:spring-beans to version 5.3.14-root.io.2.
  • Update org.springframework:spring-beans to version 5.3.14-aikido.3.
  • Update io.root.org.springframework:spring-beans to version 5.3.14-root.io.3.
  • Update cisco cx_cloud_agent to version 2.1.0 or later.
  • Update oracle mysql_enterprise_monitor to version 8.0.29 or later.
  • Update siemens operation_scheduler to version 2.0.4 or later.
  • Update siemens simatic_speech_assistant_for_machines to version 1.2.1 or later.
  • Update siemens sinec_network_management_system to version 1.0.3 or later.
Affected software
Ecosystem VendorProductAffected versions
– vmware spring framework All versions
maven springframework org.springframework:spring-beans >= 5.3.0, < 5.3.18
< 5.2.20.RELEASE
Fix: upgrade to 5.3.18
maven springframework org.springframework:spring-webmvc >= 5.3.0, < 5.3.18
< 5.2.20.RELEASE
Fix: upgrade to 5.3.18
maven springframework org.springframework.boot:spring-boot-starter-web < 2.5.12
>= 2.6.0, < 2.6.6
Fix: upgrade to 2.5.12
maven springframework org.springframework:spring-webflux >= 5.3.0, < 5.3.18
< 5.2.20.RELEASE
Fix: upgrade to 5.3.18
maven springframework org.springframework.boot:spring-boot-starter-webflux < 2.5.12
>= 2.6.0, < 2.6.6
Fix: upgrade to 2.5.12
– vmware spring_framework < 5.2.20
>= 5.3.0, < 5.3.18
cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*
– cisco cx_cloud_agent < 2.1.0
cpe:2.3:a:cisco:cx_cloud_agent:*:*:*:*:*:*:*:*
– oracle communications_cloud_native_core_automated_test_suite 1.9.0
22.1.0
cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.9.0:*:*:*:*:*:*:*
– oracle communications_cloud_native_core_console 1.9.0
22.1.0
cpe:2.3:a:oracle:communications_cloud_native_core_console:1.9.0:*:*:*:*:*:*:*
– oracle communications_cloud_native_core_network_exposure_function 22.1.0
cpe:2.3:a:oracle:communications_cloud_native_core_network_exposure_function:22.1.0:*:*:*:*:*:*:*
– oracle communications_cloud_native_core_network_function_cloud_native_environment 1.10.0
22.1.0
cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:1.10.0:*:*:*:*:*:*:*
– oracle communications_cloud_native_core_network_repository_function 1.15.0
22.1.0
cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.15.0:*:*:*:*:*:*:*
– oracle communications_cloud_native_core_network_slice_selection_function 1.8.0
1.15.0
22.1.0
cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.8.0:*:*:*:*:*:*:*
– oracle communications_cloud_native_core_policy 1.15.0
22.1.0
cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.15.0:*:*:*:*:*:*:*
– oracle communications_cloud_native_core_security_edge_protection_proxy 1.7.0
22.1.0
cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:1.7.0:*:*:*:*:*:*:*
– oracle communications_cloud_native_core_unified_data_repository 1.15.0
22.1.0
cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:1.15.0:*:*:*:*:*:*:*
– oracle communications_policy_management 12.6.0.0.0
cpe:2.3:a:oracle:communications_policy_management:12.6.0.0.0:*:*:*:*:*:*:*
– oracle financial_services_analytical_applications_infrastructure 8.1.1
8.1.2.0
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.1:*:*:*:*:*:*:*
– oracle financial_services_behavior_detection_platform 8.1.1.0
8.1.1.1
8.1.2.0
cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.1.0:*:*:*:*:*:*:*
– oracle financial_services_enterprise_case_management 8.1.1.0
8.1.1.1
8.1.2.0
cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.1.0:*:*:*:*:*:*:*
– oracle mysql_enterprise_monitor < 8.0.29
cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*
– oracle product_lifecycle_analytics 3.6.1
cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:*
– oracle retail_xstore_point_of_service 20.0.1
21.0.0
cpe:2.3:a:oracle:retail_xstore_point_of_service:20.0.1:*:*:*:*:*:*:*
– oracle sd-wan_edge 9.0
9.1
cpe:2.3:a:oracle:sd-wan_edge:9.0:*:*:*:*:*:*:*
– siemens operation_scheduler < 2.0.4
cpe:2.3:a:siemens:operation_scheduler:*:*:*:*:*:*:*:*
– siemens sipass_integrated 2.80
2.85
cpe:2.3:a:siemens:sipass_integrated:2.80:*:*:*:*:*:*:*
– siemens siveillance_identity 1.5
1.6
cpe:2.3:a:siemens:siveillance_identity:1.5:*:*:*:*:*:*:*
– veritas access_appliance 7.4.3
7.4.3.100
7.4.3.200
cpe:2.3:a:veritas:access_appliance:7.4.3:*:*:*:*:*:*:*
– veritas flex_appliance 1.3
2.0
2.0.1
2.0.2
2.1
cpe:2.3:a:veritas:flex_appliance:1.3:*:*:*:*:*:*:*
– veritas netbackup_flex_scale_appliance 2.1
3.0
cpe:2.3:a:veritas:netbackup_flex_scale_appliance:2.1:*:*:*:*:*:*:*
– veritas netbackup_appliance 4.0
4.0.0.1
4.1
4.1.0.1
cpe:2.3:h:veritas:netbackup_appliance:4.0:*:*:*:*:*:*:*
– veritas netbackup_virtual_appliance 4.0
4.0.0.1
4.1
4.1.0.1
cpe:2.3:h:veritas:netbackup_virtual_appliance:4.0:*:*:*:*:*:*:*
– siemens simatic_speech_assistant_for_machines < 1.2.1
cpe:2.3:a:siemens:simatic_speech_assistant_for_machines:*:*:*:*:*:*:*:*
– siemens sinec_network_management_system < 1.0.3
cpe:2.3:a:siemens:sinec_network_management_system:*:*:*:*:*:*:*:*
– oracle commerce_platform 11.3.2
cpe:2.3:a:oracle:commerce_platform:11.3.2:*:*:*:*:*:*:*
– oracle communications_cloud_native_core_binding_support_function 22.1.3
cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:22.1.3:*:*:*:*:*:*:*
– oracle communications_unified_inventory_management 7.4.1
7.4.2
7.5.0
cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.1:*:*:*:*:*:*:*
– oracle retail_bulk_data_integration 16.0.3
cpe:2.3:a:oracle:retail_bulk_data_integration:16.0.3:*:*:*:*:*:*:*
– oracle retail_customer_management_and_segmentation_foundation 17.0
18.0
19.0
cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:17.0:*:*:*:*:*:*:*
– oracle retail_financial_integration 14.1.3.2
15.0.3.1
16.0.3
19.0.1
cpe:2.3:a:oracle:retail_financial_integration:14.1.3.2:*:*:*:*:*:*:*
– oracle retail_integration_bus 14.1.3.2
15.0.3.1
16.0.3
19.0.1
cpe:2.3:a:oracle:retail_integration_bus:14.1.3.2:*:*:*:*:*:*:*
– oracle retail_merchandising_system 16.0.3
19.0.1
cpe:2.3:a:oracle:retail_merchandising_system:16.0.3:*:*:*:*:*:*:*
– oracle weblogic_server 12.2.1.3.0
12.2.1.4.0
14.1.1.0.0
cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:*
Root:Maven – org.springframework:spring-beans < 5.3.14-aikido.2
< 5.3.14-aikido.3
Fix: upgrade to 5.3.14-aikido.2
Root:Maven – io.root.org.springframework:spring-beans < 5.3.14-root.io.2
< 5.3.14-root.io.3
Fix: upgrade to 5.3.14-root.io.2
Original advisory text
Spring Framework JDK 9+ Remote Code Execution Vulnerability
Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
Severity
9.8 Critical
Exploitation
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
EPSS 100%
Type
CWE-74Injection
CWE-94Code Injection
Timeline
Published24 Sep 2026
Updated24 Sep 2026
First seen6 Mar 2026
Track software like this
Free during beta