Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-22963

99
FAUCET Score

CVE-2022-22963 is a critical remote code execution (RCE) vulnerability affecting Spring Cloud Function versions 3.1.6, 3.2.2, and older unsupported versions, specifically impacting Oracle and VMware products. This flaw allows an unauthenticated attacker to craft a malicious SpEL expression within routing functionality, leading to arbitrary code execution and access to local resources. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, this vulnerability poses a severe risk. It is actively exploited in the wild, with public exploit code available in Metasploit and Nuclei, and has garnered significant community discussion and media coverage, highlighting its widespread impact and potential for exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
<= 3.1.6CPE matchmatch criteria
cpe:2.3:a:vmware:spring_cloud_function:*:*:*:*:*:*:*:*
>= 3.2.0, <= 3.2.2CPE matchmatch criteria
cpe:2.3:a:vmware:spring_cloud_function:*:*:*:*:*:*:*:*
14.5CPE matchmatch criteria
cpe:2.3:a:oracle:banking_branch:14.5:*:*:*:*:*:*:*
14.5CPE matchmatch criteria
cpe:2.3:a:oracle:banking_cash_management:14.5:*:*:*:*:*:*:*
14.5CPE matchmatch criteria
cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.5:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
99.94%
Probability of exploitation in next 30 days
EPSS Percentile
100.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
Added to KEV · Aug 25, 2022
Metasploit: Spring Cloud Function SpEL Injection · Mar 29, 2022
Nuclei: CVE-2022-22963 · Mar 27, 2022
ExploitDB: EDB-51577 · Jul 11, 2023
This CVE's current EPSS score of 0.9994 is in the 100th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (21)

hppatch availablevia llm_extracted
View patch
mavenpatch availablevia ghsa
Product: org.springframework.cloud:spring-cloud-function-contextFixed in: 3.1.7
mavenpatch availablevia ghsa
Product: org.springframework.cloud:spring-cloud-function-contextFixed in: 3.2.3
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Openshift Serveless 1.21Fixed in: openshift-serverless-1/client-kn-rhel8:1.0.1-3
View patch
redhatpatch availablevia redhat_api
Product: Openshift Serveless 1.21Fixed in: openshift-serverless-1/kn-cli-artifacts-rhel8:1.0.1-3
View patch
redhatpatch availablevia redhat_api
Product: Openshift Serverless 1 on RHEL 8Fixed in: openshift-serverless-clients-0:1.0.1-2.el8
View patch
apachevendor investigatingvia llm_extracted
barracudavendor investigatingvia llm_extracted
bentomlvendor investigatingvia llm_extracted
boschvendor investigatingvia llm_extracted
clamavvendor investigatingvia llm_extracted
consulvendor investigatingvia llm_extracted
dogukanurkervendor investigatingvia llm_extracted
View patch
freshrssvendor investigatingvia llm_extracted
kenticovendor investigatingvia llm_extracted
View patch
kongvendor investigatingvia llm_extracted
View patch
linuxvendor investigatingvia llm_extracted
View patch
qdrantvendor investigatingvia llm_extracted
symantecvendor investigatingvia llm_extracted
verbbvendor investigatingvia llm_extracted

Vendor Advisories (17)

hpllm-hp-f30dcc3f021e8cb4

Spring4Shell NO IMPACT

Apr 9, 2022
linuxllm-linux-4bf4d201a0280490

Spring4Shell NO IMPACT

Apr 9, 2022
bentomlllm-bentoml-c66f51a1d644fe92

Spring4Shell NO IMPACT

Apr 9, 2022
kongllm-kong-0158b4948d74137b

Spring4Shell NO IMPACT

Apr 9, 2022
kenticollm-kentico-ec17937794bfef52

Spring4Shell NO IMPACT

Apr 9, 2022
dogukanurkerllm-dogukanurker-e96647a3fc6f23b8

Spring4Shell NO IMPACT

Apr 9, 2022
apachellm-apache-247594edfacc8f27

Spring4Shell NO IMPACT

Apr 9, 2022
mavenGHSA-6v73-fgf6-w5j7critical

Spring Cloud Function Code Injection with a specially crafted SpEL as a routing expression

Apr 3, 2022
qdrantllm-qdrant-fd4a3a29ded9a702

Remote Code Execution Vulnerability in the Spring Framework

Apr 1, 2022
clamavllm-clamav-3b18e907135e442c

Remote Code Execution Vulnerability in the Spring Framework

Apr 1, 2022
verbbllm-verbb-42d7ff8272d23fba

Remote Code Execution Vulnerability in the Spring Framework

Apr 1, 2022
boschllm-bosch-83770d6a0b4b140b

Remote Code Execution Vulnerability in the Spring Framework

Apr 1, 2022
symantecllm-symantec-9785d05e967a5f5c

Remote Code Execution Vulnerability in the Spring Framework

Apr 1, 2022
freshrssllm-freshrss-b6716213ae213ea4

Remote Code Execution Vulnerability in the Spring Framework

Apr 1, 2022
barracudallm-barracuda-3a82ab512d37c5b0

Remote Code Execution Vulnerability in the Spring Framework

Apr 1, 2022
consulllm-consul-93c9745e79a271a3

Remote Code Execution Vulnerability in the Spring Framework

Apr 1, 2022
redhatCVE-2022-22963Critical

spring-cloud-function: Remote code execution by malicious Spring Expression

Mar 29, 2022

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
packetstormsecurity.com / files/173430/Spring-Cloud-3.2.2-Remote-Command-Execution.html
ExploitThird Party AdvisoryVDB Entry
psirt.global.sonicwall.com / vuln-detail/SNWLID-2022-0005
Third Party Advisory
tanzu.vmware.com / security/cve-2022-22963
Vendor Advisory
tools.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-scf-rce-DQrHhJxH
Third Party Advisory
oracle.com / security-alerts/cpuapr2022.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujul2022.html
PatchThird Party Advisory