Skip to content
COOEY

EXPOSURES › CVE-2022-22947

CVE-2022-22947

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-05-16 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-22947 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 rceexploited-in-wildunpatched

VMware Spring Cloud Gateway allows code injection via its exposed and unsecured Actuator endpoint when enabled.

VMware Spring Cloud Gateway applications are vulnerable to code injection if the Gateway Actuator endpoint is enabled, exposed, and unsecured. This failure matters to DIB organizations because code injection can lead to arbitrary code execution, compromising system integrity and violating CMMC/NIST 800-171 requirements for access control and system integrity. Organizations must ensure Actuator endpoints are disabled or properly secured to prevent exploitation.

Shame score — A known code injection vulnerability in a widely deployed VMware product that was actively exploited (KEV) demonstrates negligent exposure of a critical endpoint, risking system compromise and violating compliance mandates.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
VMware Government Services (VGS)
VMware, Inc.
Authorized
Workspace ONE
VMware, Inc.
Authorized