CVE-2022-22963 is a critical remote code execution (RCE) vulnerability affecting Spring Cloud Function versions 3.1.6, 3.2.2, and older unsupported versions, specifically impacting Oracle and VMware products. This flaw allows an unauthenticated attacker to craft a malicious SpEL expression within routing functionality, leading to arbitrary code execution and access to local resources. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, this vulnerability poses a severe risk. It is actively exploited in the wild, with public exploit code available in Metasploit and Nuclei, and has garnered significant community discussion and media coverage, highlighting its widespread impact and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.1.6CPE matchmatch criteria | cpe:2.3:a:vmware:spring_cloud_function:*:*:*:*:*:*:*:* | ||
>= 3.2.0, <= 3.2.2CPE matchmatch criteria | cpe:2.3:a:vmware:spring_cloud_function:*:*:*:*:*:*:*:* | ||
14.5CPE matchmatch criteria | cpe:2.3:a:oracle:banking_branch:14.5:*:*:*:*:*:*:* | ||
14.5CPE matchmatch criteria | cpe:2.3:a:oracle:banking_cash_management:14.5:*:*:*:*:*:*:* | ||
14.5CPE matchmatch criteria | cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Spring4Shell NO IMPACT
Apr 9, 2022Spring4Shell NO IMPACT
Apr 9, 2022Spring4Shell NO IMPACT
Apr 9, 2022Spring4Shell NO IMPACT
Apr 9, 2022Spring4Shell NO IMPACT
Apr 9, 2022Spring4Shell NO IMPACT
Apr 9, 2022Spring4Shell NO IMPACT
Apr 9, 2022Spring Cloud Function Code Injection with a specially crafted SpEL as a routing expression
Apr 3, 2022Remote Code Execution Vulnerability in the Spring Framework
Apr 1, 2022Remote Code Execution Vulnerability in the Spring Framework
Apr 1, 2022Remote Code Execution Vulnerability in the Spring Framework
Apr 1, 2022Remote Code Execution Vulnerability in the Spring Framework
Apr 1, 2022Remote Code Execution Vulnerability in the Spring Framework
Apr 1, 2022Remote Code Execution Vulnerability in the Spring Framework
Apr 1, 2022Remote Code Execution Vulnerability in the Spring Framework
Apr 1, 2022Remote Code Execution Vulnerability in the Spring Framework
Apr 1, 2022spring-cloud-function: Remote code execution by malicious Spring Expression
Mar 29, 2022