Skip to content
COOEY

FAIL › dossier

VMware Tanzu

VENDOR

· dossier confidence 20%

VMware Tanzu delivers container orchestration but carries a history of critical RCE vulnerabilities in Spring-based components, including CVE-2018-1273 actively exploited in ransomware attacks.

PROFILE
CategoryvendorWhat they doVMware Tanzu provides container orchestration and Kubernetes management solutions for enterprise and cloud-native workloads. Websitehttps://www.vmware.com ↗
SECURITY POSTURE

History of critical RCE vulnerabilities in Tanzu Spring components, including CVE-2018-1273 actively exploited in ransomware attacks.

Notable failures
  • CVE-2018-1273 critical RCE in Spring Data Commons exploited in ransomware
  • CVE-2022-22963 high RCE in Spring Cloud Function routing
  • CVE-2020-5410 high path traversal in Cloud Config
Patterns: Spring-based Tanzu components with RCE vulnerabilities; Configuration management vulnerabilities in Spring Cloud
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2022-03-25 CVE-2018-1273 critical VMware Tanzu Spring Data Commons contained a remote code execution vulnerability actively exploited in ransomware attacks, impacting DIB organizations using this software stack.
2022-08-25 CVE-2022-22963 high VMware Tanzu Spring Cloud Function RCE
2022-03-25 CVE-2020-5410 high A path traversal flaw in VMware Tanzu Spring Cloud Config allowed attackers to serve arbitrary files, leading to potential data exposure and compliance violations.
Open questions: Current remediation status of CVE-2018-1273 · Frequency of patching for Spring-based components
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-31 03:59:08.321035+00:00