Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-22965

98
FAUCET Score

CVE-2022-22965, known as Spring4Shell, is a critical remote code execution (RCE) vulnerability affecting Spring MVC and Spring WebFlux applications running on JDK 9+ and deployed as WAR files on Tomcat. This flaw impacts products from vendors like Cisco, Oracle, Siemens, Veritas, and VMware. With a CVSS score of 9.8, it allows unauthenticated attackers to execute arbitrary code with high impact on confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, with public exploit modules available in Metasploit and Nuclei, and has garnered significant community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.2.20CPE matchmatch criteria
cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*
>= 5.3.0, < 5.3.18CPE matchmatch criteria
cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*
< 2.1.0CPE matchmatch criteria
cpe:2.3:a:cisco:cx_cloud_agent:*:*:*:*:*:*:*:*
1.9.0CPE matchmatch criteria
cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.9.0:*:*:*:*:*:*:*
22.1.0CPE matchmatch criteria
cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:22.1.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
99.68%
Probability of exploitation in next 30 days
EPSS Percentile
99.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Added to KEV · Apr 4, 2022
Metasploit: Spring Framework Class property RCE (Spring4Shell) · Mar 31, 2022
Nuclei: CVE-2022-22965 · Apr 1, 2022
This CVE's current EPSS score of 0.9968 is in the 100th percentile among its peer group of 36,821 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (36)

mavenpatch availablevia ghsa
Product: org.springframework:spring-beansFixed in: 5.3.18
mavenpatch availablevia ghsa
Product: org.springframework:spring-webmvcFixed in: 5.3.18
mavenpatch availablevia ghsa
Product: org.springframework.boot:spring-boot-starter-webFixed in: 2.5.12
mavenpatch availablevia ghsa
Product: org.springframework.boot:spring-boot-starter-webFixed in: 2.6.6
mavenpatch availablevia ghsa
Product: org.springframework:spring-webfluxFixed in: 5.3.18
mavenpatch availablevia ghsa
Product: org.springframework.boot:spring-boot-starter-webfluxFixed in: 2.5.12
mavenpatch availablevia ghsa
Product: org.springframework.boot:spring-boot-starter-webfluxFixed in: 2.6.6
mavenpatch availablevia ghsa
Product: org.springframework:spring-beansFixed in: 5.2.20.RELEASE
mavenpatch availablevia ghsa
Product: org.springframework:spring-webmvcFixed in: 5.2.20.RELEASE
mavenpatch availablevia ghsa
Product: org.springframework:spring-webfluxFixed in: 5.2.20.RELEASE
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: CEQ 2.2.1-1 (CVE-2022-22965)
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AMQ 7.8.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AMQ 7.9.4Fixed in: spring-webmvc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.10.2Fixed in: spring-webmvc
View patch
redhatpatch availablevia redhat_api
Product: RHDM 7.12.1 asyncFixed in: spring-webmvc
View patch
redhatpatch availablevia redhat_api
Product: RHINT Camel-K 1.6.5Fixed in: spring-beans
View patch
redhatpatch availablevia redhat_api
Product: RHPAM 7.12.1 asyncFixed in: spring-webmvc
View patch
barracudavendor investigatingvia llm_extracted
boschvendor investigatingvia llm_extracted
cephvendor investigatingvia llm_extracted
clamavvendor investigatingvia llm_extracted
consulvendor investigatingvia llm_extracted
d-linkvendor investigatingvia llm_extracted
freshrssvendor investigatingvia llm_extracted
humansignalvendor investigatingvia llm_extracted
hyperledgervendor investigatingvia llm_extracted
m2teamvendor investigatingvia llm_extracted
qdrantvendor investigatingvia llm_extracted
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Fuse 6Fixed in: spring-webmvc
redhatvendor investigatingvia redhat_api
Product: Red Hat Virtualization 4Fixed in: rhvm-dependencies
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss A-MQ 6Fixed in: spring-webmvc
roundcubevendor investigatingvia llm_extracted
symantecvendor investigatingvia llm_extracted
verbbvendor investigatingvia llm_extracted
redhatno patchvia redhat_api
Product: Red Hat Integration Camel Quarkus 1Fixed in: spring-beans

Vendor Advisories (16)

cephllm-ceph-ecdbe682351507f0CRITICAL

Improper Control of Generation of Code in Bosch MATRIX

Apr 27, 2022
humansignalllm-humansignal-39d1be2fad8d71d7CRITICAL

Improper Control of Generation of Code in Bosch MATRIX

Apr 27, 2022
d-linkllm-d-link-74da9b2108ce2974CRITICAL

Improper Control of Generation of Code in Bosch MATRIX

Apr 27, 2022
m2teamllm-m2team-35e5dc3cea8ee6afCRITICAL

Improper Control of Generation of Code in Bosch MATRIX

Apr 27, 2022
hyperledgerllm-hyperledger-44823c0a35c81b49CRITICAL

Improper Control of Generation of Code in Bosch MATRIX

Apr 27, 2022
roundcubellm-roundcube-42ea51370f90895eCRITICAL

Improper Control of Generation of Code in Bosch MATRIX

Apr 27, 2022
boschllm-bosch-83770d6a0b4b140b

Remote Code Execution Vulnerability in the Spring Framework

Apr 1, 2022
freshrssllm-freshrss-b6716213ae213ea4

Remote Code Execution Vulnerability in the Spring Framework

Apr 1, 2022
qdrantllm-qdrant-fd4a3a29ded9a702

Remote Code Execution Vulnerability in the Spring Framework

Apr 1, 2022
barracudallm-barracuda-3a82ab512d37c5b0

Remote Code Execution Vulnerability in the Spring Framework

Apr 1, 2022
symantecllm-symantec-9785d05e967a5f5c

Remote Code Execution Vulnerability in the Spring Framework

Apr 1, 2022
verbbllm-verbb-42d7ff8272d23fba

Remote Code Execution Vulnerability in the Spring Framework

Apr 1, 2022
consulllm-consul-93c9745e79a271a3

Remote Code Execution Vulnerability in the Spring Framework

Apr 1, 2022
clamavllm-clamav-3b18e907135e442c

Remote Code Execution Vulnerability in the Spring Framework

Apr 1, 2022
mavenGHSA-36p3-wjmg-h94xcritical

Remote Code Execution in Spring Framework

Mar 31, 2022
redhatCVE-2022-22965Important

spring-framework: RCE via Data Binding on JDK 9+

Mar 30, 2022

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
kb.cert.org / vuls/id/970766
US Government Resource
packetstormsecurity.com / files/166713/Spring4Shell-Code-Execution.html
ExploitThird Party AdvisoryVDB Entry
packetstormsecurity.com / files/167011/Spring4Shell-Spring-Framework-Class-Property-Remote-Code-Execution.html
Third Party AdvisoryVDB Entry
cert-portal.siemens.com / productcert/pdf/ssa-254054.pdf
PatchThird Party Advisory
psirt.global.sonicwall.com / vuln-detail/SNWLID-2022-0005
Third Party Advisory
tanzu.vmware.com / security/cve-2022-22965
MitigationVendor Advisory
tools.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67
Third Party Advisory
oracle.com / security-alerts/cpuapr2022.html
Third Party Advisory
oracle.com / security-alerts/cpujul2022.html
PatchThird Party Advisory