EXPOSURES › CVE-2022-22963
CVE-2022-22963
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 72/100
rceexploited-in-wildunpatched
VMware Tanzu Spring Cloud Function RCE
VMware Tanzu Spring Cloud Function allowed remote code execution through crafted SpEL expressions, leading to unpatched and actively exploited vulnerabilities.
Shame score — Crafted expressions enabled remote code execution and access to local resources, with known exploitation in the wild.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
AFFECTED FEDRAMP PRODUCTS · 2
| PRODUCT | STATUS |
|---|---|
| VMware Government Services (VGS) VMware, Inc. |
Authorized |
| Workspace ONE VMware, Inc. |
Authorized |