← Back

CVE-2022-22963

Published: Apr 1, 2022Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

Affected (47)

Products: Vmware: Spring Cloud Function · Oracle: Banking Branch, Banking Cash Management, Banking Corporate Lending Process Management, Banking Credit Facilities Process Management, Banking Electronic Data Exchange For Corporates, Banking Liquidity Management, Banking Origination, Banking Supply Chain Finance, Banking Trade Finance Process Management, Banking Virtual Account Management, Communications Cloud Native Core Automated Test Suite, Communications Cloud Native Core Console, Communications Cloud Native Core Network Exposure Function, Communications Cloud Native Core Network Function Cloud Native Environment, Communications Cloud Native Core Network Repository Function, Communications Cloud Native Core Network Slice Selection Function, Communications Cloud Native Core Policy, Communications Cloud Native Core Security Edge Protection Proxy, Communications Cloud Native Core Unified Data Repository, Communications Communications Policy Management, Financial Services Analytical Applications Infrastructure, Financial Services Behavior Detection Platform, Financial Services Enterprise Case Management, Mysql Enterprise Monitor, Product Lifecycle Analytics, Retail Xstore Point Of Service, Sd Wan Edge
1 product
Spring Cloud Function
27 products
Banking Branch
Banking Cash Management
Banking Liquidity Management
Banking Origination
Banking Supply Chain Finance
Mysql Enterprise Monitor
Product Lifecycle Analytics
Retail Xstore Point Of Service
Sd Wan Edge
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
Up to 3.1.6
From 3.2.0 to 3.2.2
Configuration B
45 vulnerable
Vulnerable SoftwareAffected Versions
Version 14.5
Version 14.5
Version 14.5
Version 14.5
Version 14.5
Oracle
Version 14.2
Version 14.5
Version 14.5
Version 14.5
Version 14.5
Version 14.5
Oracle
Version 1.9.0
Version 22.1.0
Oracle
Version 1.9.0
Version 22.1.0
Version 22.1.0
Oracle
Version 1.10.0
Version 22.1.0
Version 22.1.2
Oracle
Version 1.15.0
Version 22.1.0
Oracle
Version 1.8.0
Version 22.1.0
Oracle
Version 1.15.0
Version 22.1.0
Version 22.1.3
Oracle
Version 1.7.0
Version 22.1.0
Oracle
Version 1.15.0
Version 22.1.0
Version 12.6.0.0.0
Oracle
Version 8.1.1.0
Version 8.1.2.0
Oracle
Version 8.1.1.0
Version 8.1.1.1
Version 8.1.2.0
Oracle
Version 8.1.1.0
Version 8.1.1.1
Version 8.1.2.0
Up to 8.0.29
Version 3.6.1.0
Oracle
Version 20.0.1
Version 21.0.0
Oracle
Version 9.0
Version 9.1

References (13)

Source: security@vmware.com
ExploitThird Party AdvisoryVDB Entry
Source: security@vmware.com
Third Party Advisory
Source: security@vmware.com
Vendor Advisory
Source: security@vmware.com
PatchThird Party Advisory
Source: security@vmware.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.