Tracker / CVE-2022-22963
CVE-2022-22963
Exploited Critical 9.8
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
Affected products and versions
| oracle | banking_branch |
|---|---|
| oracle | banking_cash_management |
| oracle | banking_corporate_lending_process_management |
| oracle | banking_credit_facilities_process_management |
| oracle | banking_electronic_data_exchange_for_corporates |
| oracle | banking_liquidity_management |
| oracle | banking_origination |
| oracle | banking_supply_chain_finance |
| oracle | banking_trade_finance_process_management |
| oracle | banking_virtual_account_management |
| oracle | communications_cloud_native_core_automated_test_suite |
| oracle | communications_cloud_native_core_console |
| oracle | communications_cloud_native_core_network_exposure_function |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment |
| oracle | communications_cloud_native_core_network_repository_function |
| oracle | communications_cloud_native_core_network_slice_selection_function |
| oracle | communications_cloud_native_core_policy |
| oracle | communications_cloud_native_core_security_edge_protection_proxy |
| oracle | communications_cloud_native_core_unified_data_repository |
| oracle | communications_communications_policy_management |
| oracle | financial_services_analytical_applications_infrastructure |
| oracle | financial_services_behavior_detection_platform |
| oracle | financial_services_enterprise_case_management |
| oracle | mysql_enterprise_monitor · … → 8.0.29 |
| oracle | product_lifecycle_analytics |
| oracle | retail_xstore_point_of_service |
| oracle | sd-wan_edge |
| vmware | spring_cloud_function · … → 3.1.6 |
| vmware | spring_cloud_function · 3.2.0 → 3.2.2 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.