EXPOSURES › CVE-2022-22947
CVE-2022-22947
HIGH ⌖ ON CISA KEV · EXPLOITEDVMware Spring Cloud Gateway allows code injection via its exposed and unsecured Actuator endpoint when enabled.
VMware Spring Cloud Gateway applications are vulnerable to code injection if the Gateway Actuator endpoint is enabled, exposed, and unsecured. This failure matters to DIB organizations because code injection can lead to arbitrary code execution, compromising system integrity and violating CMMC/NIST 800-171 requirements for access control and system integrity. Organizations must ensure Actuator endpoints are disabled or properly secured to prevent exploitation.
Shame score — A known code injection vulnerability in a widely deployed VMware product that was actively exploited (KEV) demonstrates negligent exposure of a critical endpoint, risking system compromise and violating compliance mandates.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured.
| PRODUCT | STATUS |
|---|---|
| VMware Government Services (VGS) VMware, Inc. |
Authorized |
| Workspace ONE VMware, Inc. |
Authorized |