CVE-2022-22963

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
Code Injection
Expression Language Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vmwareCNA
---
---
CVEADP
---
---
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
vmwarespring_cloud_function
𝑥
≤ 3.1.6
vmwarespring_cloud_function
3.2.0 ≤
𝑥
≤ 3.2.2
oraclebanking_branch
14.5
oraclebanking_cash_management
14.5
oraclebanking_corporate_lending_process_management
14.5
oraclebanking_credit_facilities_process_management
14.5
oraclebanking_electronic_data_exchange_for_corporates
14.5
oraclebanking_liquidity_management
14.2
oraclebanking_liquidity_management
14.5
oraclebanking_origination
14.5
oraclebanking_supply_chain_finance
14.5
oraclebanking_trade_finance_process_management
14.5
oraclebanking_virtual_account_management
14.5
oraclecommunications_cloud_native_core_automated_test_suite
1.9.0
oraclecommunications_cloud_native_core_automated_test_suite
22.1.0
oraclecommunications_cloud_native_core_console
1.9.0
oraclecommunications_cloud_native_core_console
22.1.0
oraclecommunications_cloud_native_core_network_exposure_function
22.1.0
oraclecommunications_cloud_native_core_network_function_cloud_native_environment
1.10.0
oraclecommunications_cloud_native_core_network_function_cloud_native_environment
22.1.0
oraclecommunications_cloud_native_core_network_function_cloud_native_environment
22.1.2
oraclecommunications_cloud_native_core_network_repository_function
1.15.0
oraclecommunications_cloud_native_core_network_repository_function
22.1.0
oraclecommunications_cloud_native_core_network_slice_selection_function
1.8.0
oraclecommunications_cloud_native_core_network_slice_selection_function
22.1.0
oraclecommunications_cloud_native_core_policy
1.15.0
oraclecommunications_cloud_native_core_policy
22.1.0
oraclecommunications_cloud_native_core_policy
22.1.3
oraclecommunications_cloud_native_core_security_edge_protection_proxy
1.7.0
oraclecommunications_cloud_native_core_security_edge_protection_proxy
22.1.0
oraclecommunications_cloud_native_core_unified_data_repository
1.15.0
oraclecommunications_cloud_native_core_unified_data_repository
22.1.0
oraclecommunications_communications_policy_management
12.6.0.0.0
oraclefinancial_services_analytical_applications_infrastructure
8.1.1.0
oraclefinancial_services_analytical_applications_infrastructure
8.1.2.0
oraclefinancial_services_behavior_detection_platform
8.1.1.0
oraclefinancial_services_behavior_detection_platform
8.1.1.1
oraclefinancial_services_behavior_detection_platform
8.1.2.0
oraclefinancial_services_enterprise_case_management
8.1.1.0
oraclefinancial_services_enterprise_case_management
8.1.1.1
oraclefinancial_services_enterprise_case_management
8.1.2.0
oraclemysql_enterprise_monitor
𝑥
≤ 8.0.29
oracleproduct_lifecycle_analytics
3.6.1.0
oracleretail_xstore_point_of_service
20.0.1
oracleretail_xstore_point_of_service
21.0.0
oraclesd-wan_edge
9.0
oraclesd-wan_edge
9.1
𝑥
= Vulnerable software versions