Skip to content
COOEY

EXPOSURES › CVE-2022-22965

CVE-2022-22965

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-04-04 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-22965 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

VMware Spring Framework apps on JDK 9+ suffered remote code execution via data binding.

Spring MVC or Spring WebFlux applications running on JDK 9+ were vulnerable to remote code execution through data binding. DIB organizations must ensure their Spring Framework versions are patched, as this vulnerability was actively exploited in the wild. Failure to patch exposes systems to arbitrary code execution, violating CMMC/NIST 800-171 requirements for patch management and system integrity.

Shame score — A known RCE vulnerability in a widely used framework was actively exploited in the wild, indicating a failure to patch a critical flaw that could lead to system compromise.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
VMware Government Services (VGS)
VMware, Inc.
Authorized
Workspace ONE
VMware, Inc.
Authorized