Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2022-22965: Spring Framework apps on Java 9+ could run attacker code
CVE-2022-22965 · published 4 days ago · actively exploited
Summary
Web applications built with Spring MVC or Spring WebFlux that run on Java 9 or newer may allow an attacker to execute their own code through crafted data. This could let the attacker take control of the server or access sensitive information. Update the Spring libraries to the latest patched versions and ensure you are using a supported Java runtime.
What to do
- Update springframework org.springframework:spring-beans to version 5.3.18.
- Update springframework org.springframework:spring-webmvc to version 5.3.18.
- Update springframework org.springframework.boot:spring-boot-starter-web to version 2.5.12.
- Update springframework org.springframework.boot:spring-boot-starter-web to version 2.6.6.
- Update springframework org.springframework:spring-webflux to version 5.3.18.
- Update springframework org.springframework.boot:spring-boot-starter-webflux to version 2.5.12.
- Update springframework org.springframework.boot:spring-boot-starter-webflux to version 2.6.6.
- Update springframework org.springframework:spring-beans to version 5.2.20.RELEASE.
- Update springframework org.springframework:spring-webmvc to version 5.2.20.RELEASE.
- Update springframework org.springframework:spring-webflux to version 5.2.20.RELEASE.
- Update org.springframework:spring-beans to version 5.3.14-aikido.2.
- Update io.root.org.springframework:spring-beans to version 5.3.14-root.io.2.
- Update org.springframework:spring-beans to version 5.3.14-aikido.3.
- Update io.root.org.springframework:spring-beans to version 5.3.14-root.io.3.
- Update cisco cx_cloud_agent to version 2.1.0 or later.
- Update oracle mysql_enterprise_monitor to version 8.0.29 or later.
- Update siemens operation_scheduler to version 2.0.4 or later.
- Update siemens simatic_speech_assistant_for_machines to version 1.2.1 or later.
- Update siemens sinec_network_management_system to version 1.0.3 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | vmware | spring framework | All versions |
| maven | springframework | org.springframework:spring-beans |
>= 5.3.0, < 5.3.18 < 5.2.20.RELEASE Fix: upgrade to 5.3.18
|
| maven | springframework | org.springframework:spring-webmvc |
>= 5.3.0, < 5.3.18 < 5.2.20.RELEASE Fix: upgrade to 5.3.18
|
| maven | springframework | org.springframework.boot:spring-boot-starter-web |
< 2.5.12 >= 2.6.0, < 2.6.6 Fix: upgrade to 2.5.12
|
| maven | springframework | org.springframework:spring-webflux |
>= 5.3.0, < 5.3.18 < 5.2.20.RELEASE Fix: upgrade to 5.3.18
|
| maven | springframework | org.springframework.boot:spring-boot-starter-webflux |
< 2.5.12 >= 2.6.0, < 2.6.6 Fix: upgrade to 2.5.12
|
| – | vmware | spring_framework |
< 5.2.20 >= 5.3.0, < 5.3.18 cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:* |
| – | cisco | cx_cloud_agent |
< 2.1.0 cpe:2.3:a:cisco:cx_cloud_agent:*:*:*:*:*:*:*:* |
| – | oracle | communications_cloud_native_core_automated_test_suite |
1.9.0 22.1.0 cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.9.0:*:*:*:*:*:*:* |
| – | oracle | communications_cloud_native_core_console |
1.9.0 22.1.0 cpe:2.3:a:oracle:communications_cloud_native_core_console:1.9.0:*:*:*:*:*:*:* |
| – | oracle | communications_cloud_native_core_network_exposure_function |
22.1.0 cpe:2.3:a:oracle:communications_cloud_native_core_network_exposure_function:22.1.0:*:*:*:*:*:*:* |
| – | oracle | communications_cloud_native_core_network_function_cloud_native_environment |
1.10.0 22.1.0 cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:1.10.0:*:*:*:*:*:*:* |
| – | oracle | communications_cloud_native_core_network_repository_function |
1.15.0 22.1.0 cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.15.0:*:*:*:*:*:*:* |
| – | oracle | communications_cloud_native_core_network_slice_selection_function |
1.8.0 1.15.0 22.1.0 cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.8.0:*:*:*:*:*:*:* |
| – | oracle | communications_cloud_native_core_policy |
1.15.0 22.1.0 cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.15.0:*:*:*:*:*:*:* |
| – | oracle | communications_cloud_native_core_security_edge_protection_proxy |
1.7.0 22.1.0 cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:1.7.0:*:*:*:*:*:*:* |
| – | oracle | communications_cloud_native_core_unified_data_repository |
1.15.0 22.1.0 cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:1.15.0:*:*:*:*:*:*:* |
| – | oracle | communications_policy_management |
12.6.0.0.0 cpe:2.3:a:oracle:communications_policy_management:12.6.0.0.0:*:*:*:*:*:*:* |
| – | oracle | financial_services_analytical_applications_infrastructure |
8.1.1 8.1.2.0 cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.1:*:*:*:*:*:*:* |
| – | oracle | financial_services_behavior_detection_platform |
8.1.1.0 8.1.1.1 8.1.2.0 cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.1.0:*:*:*:*:*:*:* |
| – | oracle | financial_services_enterprise_case_management |
8.1.1.0 8.1.1.1 8.1.2.0 cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.1.0:*:*:*:*:*:*:* |
| – | oracle | mysql_enterprise_monitor |
< 8.0.29 cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:* |
| – | oracle | product_lifecycle_analytics |
3.6.1 cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:* |
| – | oracle | retail_xstore_point_of_service |
20.0.1 21.0.0 cpe:2.3:a:oracle:retail_xstore_point_of_service:20.0.1:*:*:*:*:*:*:* |
| – | oracle | sd-wan_edge |
9.0 9.1 cpe:2.3:a:oracle:sd-wan_edge:9.0:*:*:*:*:*:*:* |
| – | siemens | operation_scheduler |
< 2.0.4 cpe:2.3:a:siemens:operation_scheduler:*:*:*:*:*:*:*:* |
| – | siemens | sipass_integrated |
2.80 2.85 cpe:2.3:a:siemens:sipass_integrated:2.80:*:*:*:*:*:*:* |
| – | siemens | siveillance_identity |
1.5 1.6 cpe:2.3:a:siemens:siveillance_identity:1.5:*:*:*:*:*:*:* |
| – | veritas | access_appliance |
7.4.3 7.4.3.100 7.4.3.200 cpe:2.3:a:veritas:access_appliance:7.4.3:*:*:*:*:*:*:* |
| – | veritas | flex_appliance |
1.3 2.0 2.0.1 2.0.2 2.1 cpe:2.3:a:veritas:flex_appliance:1.3:*:*:*:*:*:*:* |
| – | veritas | netbackup_flex_scale_appliance |
2.1 3.0 cpe:2.3:a:veritas:netbackup_flex_scale_appliance:2.1:*:*:*:*:*:*:* |
| – | veritas | netbackup_appliance |
4.0 4.0.0.1 4.1 4.1.0.1 cpe:2.3:h:veritas:netbackup_appliance:4.0:*:*:*:*:*:*:* |
| – | veritas | netbackup_virtual_appliance |
4.0 4.0.0.1 4.1 4.1.0.1 cpe:2.3:h:veritas:netbackup_virtual_appliance:4.0:*:*:*:*:*:*:* |
| – | siemens | simatic_speech_assistant_for_machines |
< 1.2.1 cpe:2.3:a:siemens:simatic_speech_assistant_for_machines:*:*:*:*:*:*:*:* |
| – | siemens | sinec_network_management_system |
< 1.0.3 cpe:2.3:a:siemens:sinec_network_management_system:*:*:*:*:*:*:*:* |
| – | oracle | commerce_platform |
11.3.2 cpe:2.3:a:oracle:commerce_platform:11.3.2:*:*:*:*:*:*:* |
| – | oracle | communications_cloud_native_core_binding_support_function |
22.1.3 cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:22.1.3:*:*:*:*:*:*:* |
| – | oracle | communications_unified_inventory_management |
7.4.1 7.4.2 7.5.0 cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.1:*:*:*:*:*:*:* |
| – | oracle | retail_bulk_data_integration |
16.0.3 cpe:2.3:a:oracle:retail_bulk_data_integration:16.0.3:*:*:*:*:*:*:* |
| – | oracle | retail_customer_management_and_segmentation_foundation |
17.0 18.0 19.0 cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:17.0:*:*:*:*:*:*:* |
| – | oracle | retail_financial_integration |
14.1.3.2 15.0.3.1 16.0.3 19.0.1 cpe:2.3:a:oracle:retail_financial_integration:14.1.3.2:*:*:*:*:*:*:* |
| – | oracle | retail_integration_bus |
14.1.3.2 15.0.3.1 16.0.3 19.0.1 cpe:2.3:a:oracle:retail_integration_bus:14.1.3.2:*:*:*:*:*:*:* |
| – | oracle | retail_merchandising_system |
16.0.3 19.0.1 cpe:2.3:a:oracle:retail_merchandising_system:16.0.3:*:*:*:*:*:*:* |
| – | oracle | weblogic_server |
12.2.1.3.0 12.2.1.4.0 14.1.1.0.0 cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:* |
| Root:Maven | – | org.springframework:spring-beans |
< 5.3.14-aikido.2 < 5.3.14-aikido.3 Fix: upgrade to 5.3.14-aikido.2
|
| Root:Maven | – | io.root.org.springframework:spring-beans |
< 5.3.14-root.io.2 < 5.3.14-root.io.3 Fix: upgrade to 5.3.14-root.io.2
|
Original advisory text
Spring Framework JDK 9+ Remote Code Execution Vulnerability
Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-22965
- https://github.com/spring-projects/spring-framework/commit/002546b3e4b8d791ea6ac...
- https://github.com/spring-projects/spring-boot/releases/tag/v2.5.12
- https://github.com/spring-projects/spring-boot/releases/tag/v2.6.6
- https://github.com/spring-projects/spring-framework/releases/tag/v5.2.20.RELEASE
- https://github.com/spring-projects/spring-framework/releases/tag/v5.3.18
- https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement
- https://tanzu.vmware.com/security/cve-2022-22965
- https://cert-portal.siemens.com/productcert/pdf/ssa-254054.pdf
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-j...
- https://www.oracle.com/security-alerts/cpuapr2022.html
- http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.html
- http://packetstormsecurity.com/files/167011/Spring4Shell-Spring-Framework-Class-...
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.kb.cert.org/vuls/id/970766
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-...
- https://github.com/advisories/GHSA-36p3-wjmg-h94x
Severity
9.8
Critical
Exploitation
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
EPSS 100%
Type
CWE-74Injection
CWE-94Code Injection
Timeline
Published24 Sep 2026
Updated24 Sep 2026
First seen6 Mar 2026
Track software like this
Free during beta