CVE-2022-22965
01.04.2022, 23:15
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
Vendor | Product | Version |
---|---|---|
vmware | spring_framework | 𝑥 < 5.2.20 |
vmware | spring_framework | 5.3.0 ≤ 𝑥 < 5.3.18 |
cisco | cx_cloud_agent | 𝑥 < 2.1.0 |
oracle | communications_cloud_native_core_automated_test_suite | 1.9.0 |
oracle | communications_cloud_native_core_automated_test_suite | 22.1.0 |
oracle | communications_cloud_native_core_console | 1.9.0 |
oracle | communications_cloud_native_core_console | 22.1.0 |
oracle | communications_cloud_native_core_network_exposure_function | 22.1.0 |
oracle | communications_cloud_native_core_network_function_cloud_native_environment | 1.10.0 |
oracle | communications_cloud_native_core_network_function_cloud_native_environment | 22.1.0 |
oracle | communications_cloud_native_core_network_repository_function | 1.15.0 |
oracle | communications_cloud_native_core_network_repository_function | 22.1.0 |
oracle | communications_cloud_native_core_network_slice_selection_function | 1.8.0 |
oracle | communications_cloud_native_core_network_slice_selection_function | 1.15.0 |
oracle | communications_cloud_native_core_network_slice_selection_function | 22.1.0 |
oracle | communications_cloud_native_core_policy | 1.15.0 |
oracle | communications_cloud_native_core_policy | 22.1.0 |
oracle | communications_cloud_native_core_security_edge_protection_proxy | 1.7.0 |
oracle | communications_cloud_native_core_security_edge_protection_proxy | 22.1.0 |
oracle | communications_cloud_native_core_unified_data_repository | 1.15.0 |
oracle | communications_cloud_native_core_unified_data_repository | 22.1.0 |
oracle | communications_policy_management | 12.6.0.0.0 |
oracle | financial_services_analytical_applications_infrastructure | 8.1.1 |
oracle | financial_services_analytical_applications_infrastructure | 8.1.2.0 |
oracle | financial_services_behavior_detection_platform | 8.1.1.0 |
oracle | financial_services_behavior_detection_platform | 8.1.1.1 |
oracle | financial_services_behavior_detection_platform | 8.1.2.0 |
oracle | financial_services_enterprise_case_management | 8.1.1.0 |
oracle | financial_services_enterprise_case_management | 8.1.1.1 |
oracle | financial_services_enterprise_case_management | 8.1.2.0 |
oracle | mysql_enterprise_monitor | 𝑥 < 8.0.29 |
oracle | product_lifecycle_analytics | 3.6.1 |
oracle | retail_xstore_point_of_service | 20.0.1 |
oracle | retail_xstore_point_of_service | 21.0.0 |
oracle | sd-wan_edge | 9.0 |
oracle | sd-wan_edge | 9.1 |
siemens | operation_scheduler | 𝑥 < 2.0.4 |
siemens | sipass_integrated | 2.80 |
siemens | sipass_integrated | 2.85 |
siemens | siveillance_identity | 1.5 |
siemens | siveillance_identity | 1.6 |
veritas | access_appliance | 7.4.3 |
veritas | access_appliance | 7.4.3.100 |
veritas | access_appliance | 7.4.3.200 |
veritas | access_appliance | 7.4.3 |
veritas | access_appliance | 7.4.3.100 |
veritas | access_appliance | 7.4.3.200 |
veritas | flex_appliance | 1.3 |
veritas | flex_appliance | 2.0 |
veritas | flex_appliance | 2.0.1 |
veritas | flex_appliance | 2.0.2 |
veritas | flex_appliance | 2.1 |
veritas | netbackup_flex_scale_appliance | 2.1 |
veritas | netbackup_flex_scale_appliance | 3.0 |
veritas | netbackup_appliance | 4.0 |
veritas | netbackup_appliance | 4.0.0.1:maintenance_release1 |
veritas | netbackup_appliance | 4.0.0.1:maintenance_release2 |
veritas | netbackup_appliance | 4.0.0.1:maintenance_release3 |
veritas | netbackup_appliance | 4.1 |
veritas | netbackup_appliance | 4.1.0.1:maintenance_release1 |
veritas | netbackup_appliance | 4.1.0.1:maintenance_release2 |
veritas | netbackup_virtual_appliance | 4.0 |
veritas | netbackup_virtual_appliance | 4.0.0.1:maintenance_release1 |
veritas | netbackup_virtual_appliance | 4.0.0.1:maintenance_release2 |
veritas | netbackup_virtual_appliance | 4.0.0.1:maintenance_release3 |
veritas | netbackup_virtual_appliance | 4.1 |
veritas | netbackup_virtual_appliance | 4.1.0.1:maintenance_release1 |
veritas | netbackup_virtual_appliance | 4.1.0.1:maintenance_release2 |
siemens | operation_scheduler | 𝑥 < 2.0.4 |
siemens | simatic_speech_assistant_for_machines | 𝑥 < 1.2.1 |
siemens | sinec_network_management_system | 𝑥 < 1.0.3 |
siemens | sipass_integrated | 2.80 |
siemens | sipass_integrated | 2.85 |
siemens | siveillance_identity | 1.5 |
siemens | siveillance_identity | 1.6 |
oracle | commerce_platform | 11.3.2 |
oracle | communications_cloud_native_core_binding_support_function | 22.1.3 |
oracle | communications_unified_inventory_management | 7.4.1 |
oracle | communications_unified_inventory_management | 7.4.2 |
oracle | communications_unified_inventory_management | 7.5.0 |
oracle | retail_bulk_data_integration | 16.0.3 |
oracle | retail_customer_management_and_segmentation_foundation | 17.0 |
oracle | retail_customer_management_and_segmentation_foundation | 18.0 |
oracle | retail_customer_management_and_segmentation_foundation | 19.0 |
oracle | retail_financial_integration | 14.1.3.2 |
oracle | retail_financial_integration | 15.0.3.1 |
oracle | retail_financial_integration | 16.0.3 |
oracle | retail_financial_integration | 19.0.1 |
oracle | retail_integration_bus | 14.1.3.2 |
oracle | retail_integration_bus | 15.0.3.1 |
oracle | retail_integration_bus | 16.0.3 |
oracle | retail_integration_bus | 19.0.1 |
oracle | retail_merchandising_system | 16.0.3 |
oracle | retail_merchandising_system | 19.0.1 |
oracle | weblogic_server | 12.2.1.3.0 |
oracle | weblogic_server | 12.2.1.4.0 |
oracle | weblogic_server | 14.1.1.0.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References