EXPOSURES › CVE-2022-22965
CVE-2022-22965
HIGH ⌖ ON CISA KEV · EXPLOITEDVMware Spring Framework apps on JDK 9+ suffered remote code execution via data binding.
Spring MVC or Spring WebFlux applications running on JDK 9+ were vulnerable to remote code execution through data binding. DIB organizations must ensure their Spring Framework versions are patched, as this vulnerability was actively exploited in the wild. Failure to patch exposes systems to arbitrary code execution, violating CMMC/NIST 800-171 requirements for patch management and system integrity.
Shame score — A known RCE vulnerability in a widely used framework was actively exploited in the wild, indicating a failure to patch a critical flaw that could lead to system compromise.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
| PRODUCT | STATUS |
|---|---|
| VMware Government Services (VGS) VMware, Inc. |
Authorized |
| Workspace ONE VMware, Inc. |
Authorized |