imPC@ndo IT

Tracker / CVE-2022-22965

CVE-2022-22965

Exploited Critical 9.8

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

Affected products and versions

cisco cx_cloud_agent · … → 2.1.0
oracle commerce_platform
oracle communications_cloud_native_core_automated_test_suite
oracle communications_cloud_native_core_binding_support_function
oracle communications_cloud_native_core_console
oracle communications_cloud_native_core_network_exposure_function
oracle communications_cloud_native_core_network_function_cloud_native_environment
oracle communications_cloud_native_core_network_repository_function
oracle communications_cloud_native_core_network_slice_selection_function
oracle communications_cloud_native_core_policy
oracle communications_cloud_native_core_security_edge_protection_proxy
oracle communications_cloud_native_core_unified_data_repository
oracle communications_policy_management
oracle communications_unified_inventory_management
oracle financial_services_analytical_applications_infrastructure
oracle financial_services_behavior_detection_platform
oracle financial_services_enterprise_case_management
oracle mysql_enterprise_monitor · … → 8.0.29
oracle product_lifecycle_analytics
oracle retail_bulk_data_integration
oracle retail_customer_management_and_segmentation_foundation
oracle retail_financial_integration
oracle retail_integration_bus
oracle retail_merchandising_system
oracle retail_xstore_point_of_service
oracle sd-wan_edge
oracle weblogic_server
siemens operation_scheduler · … → 2.0.4
siemens simatic_speech_assistant_for_machines · … → 1.2.1
siemens sinec_network_management_system · … → 1.0.3
siemens sipass_integrated
siemens siveillance_identity
veritas access_appliance
veritas flex_appliance
veritas netbackup_appliance
veritas netbackup_flex_scale_appliance
veritas netbackup_virtual_appliance
vmware spring_framework · … → 5.2.20
vmware spring_framework · 5.3.0 → 5.3.18

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References