CVE-2010-1622
published 2010-06-21CVE-2010-1622: SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via…
PriorityP261medium6CVSS 2.0
AVNACMAuSCPIPAP
EXPLOIT
EPSS
52.00%
98.8th percentile
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
| paloalto | pan-os | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
SIDs: 30790-30793, 59388, and 59416
- →Detect HTTP requests containing the exploit string 'class.classLoader.URLs[0]=jar:' targeting Spring Framework endpoints — this is the original CVE-2010-1622 attack pattern. ↗
- →Monitor for JSP webshell files dropped in the Tomcat ROOT directory, particularly named shell.jsp, tomcatwar.jsp, myshell.jsp, wpz.jsp, 0xd0m7.jsp, or shell7.jsp. ↗
- →Detect webshell interactions using URL parameters '&pwd=j&cmd=' (password 'j', command via 'cmd') or '&id=' as authentication/command parameters — characteristic of publicly available SpringShell PoC webshells. ↗
- →Alert on Tomcat logging configuration modification via HTTP request parameters — exploitation abuses class loader access to overwrite log configuration and write a JSP webshell. ↗
- →Use Kaspersky verdict names PDM:Exploit.Win32.Generic, UMIDS:Intrusion.Generic.Agent.gen, and Intrusion.Generic.CVE-*.* for endpoint detection of exploitation attempts. ↗
- →CVE-2010-1622 exploitation bypasses the class.classLoader and getProtectionDomain() block list fix; on JDK 9+, the Java 9 Platform Module System (getModule) provides an alternative path to the class loader — monitor for HTTP parameters referencing 'class.module.classLoader'. ↗
- ·CVE-2010-1622 exploitation requires the application to expose Spring data binding with no proper restriction on class.classLoader access; the original fix added a block list for Class.getClassLoader() and getProtectionDomain(), which was later bypassed in CVE-2022-22965 via JDK 9+ module system. ↗
- ·The Spring Boot executable JAR deployment is NOT vulnerable to the known exploit chain; exploitation requires WAR packaging served by Apache Tomcat, GlassFish, or Payara. ↗
- ·Exploitation of the class loader via CVE-2010-1622 no longer works in patched versions (2.5.6.SEC02+), but the JDK 9 module system introduced a new bypass path used in CVE-2022-22965. ↗
CVSS provenance
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
vendor_redhat6.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2010-1622 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
Red Hat
3.0.3): Arbitrary Java code execution via an HTTP request containing a specially-crafted .jar file
vendor_redhat·2010-06-17·CVSS 6.0
CVE-2010-1622 [MEDIUM] CWE-96 3.0.3): Arbitrary Java code execution via an HTTP request containing a specially-crafted .jar file
3.0.3): Arbitrary Java code execution via an HTTP request containing a specially-crafted .jar file
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file.
Statement: This issue did not affect the versions of the SpringSource Spring Framework, as shipped with JBoss Enterprise Application Platform v4.2.0, v4.3.0, or v.5.0.0.
OSV
Improper Control of Generation of Code ('Code Injection') in Spring Framework
osv·2022-05-17
CVE-2010-1622 [MEDIUM] Improper Control of Generation of Code ('Code Injection') in Spring Framework
Improper Control of Generation of Code ('Code Injection') in Spring Framework
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing `class.classLoader.URLs[0]=jar:` followed by a URL of a crafted .jar file.
GHSA
Improper Control of Generation of Code ('Code Injection') in Spring Framework
ghsa·2022-05-17
CVE-2010-1622 [MEDIUM] CWE-94 Improper Control of Generation of Code ('Code Injection') in Spring Framework
Improper Control of Generation of Code ('Code Injection') in Spring Framework
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing `class.classLoader.URLs[0]=jar:` followed by a URL of a crafted .jar file.
No detection rules found.
Securelist
Spring4Shell (CVE-2022-22965): details and mitigations
blogs_securelist·2022-04-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] Spring4Shell (CVE-2022-22965): details and mitigations
Table of Contents
- CVE-2022-22965 and CVE-2022-22963: technical details
- Mitigations for Spring vulnerabilities exploitation
- Indicators of Compromise
Authors
- AMR
Last week researchers found the critical vulnerability CVE-2022-22965 in Spring – the open source Java framework. Using the vulnerability, an attacker can execute arbitrary code on a remote web server, which makes CVE-2022-22965 a critical threat, given the Spring framework’s popularity. By analogy with the infamous Log4Shell threat, the vulnerability was named Spring4Shell.
## CVE-2022-22965 and CVE-2022-22963: technical details
CVE-2022-22965 (Spring4Shell, SpringShell) is a vulnerability in the Spring Framework that uses data binding functionality to bind data stored within an HTTP request to certain objects used b
Securelist
Spring4Shell (CVE-2022-22965): details and mitigations
blogs_securelist·2022-04-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] Spring4Shell (CVE-2022-22965): details and mitigations
Table of Contents
CVE-2022-22965 and CVE-2022-22963: technical details
Mitigations for Spring vulnerabilities exploitation
Indicators of Compromise
Authors
AMR
Last week researchers found the critical vulnerability CVE-2022-22965 in Spring – the open source Java framework. Using the vulnerability, an attacker can execute arbitrary code on a remote web server, which makes CVE-2022-22965 a critical threat, given the Spring framework’s popularity. By analogy with the infamous Log4Shell threat , the vulnerability was named Spring4Shell.
## CVE-2022-22965 and CVE-2022-22963: technical details
CVE-2022-22965 (Spring4Shell, SpringShell) is a vulnerability in the Spring Framework that uses data binding functionality to bind data stored within an HTTP request to certain objects used by an a
Wiz
Addressing the Spring4Shell and CVE-2022-22963 RCE vulnerabilities in cloud environments | Wiz Blog
blogs_wiz·2022-04-01·CVSS 6.0
CVE-2022-22965 [MEDIUM] Addressing the Spring4Shell and CVE-2022-22963 RCE vulnerabilities in cloud environments | Wiz Blog
Updated April 13th, 2022 to include the latest available information about CVE-2022-22965, further explanation of dependencies in Spring Framework, and data about the prevalence of this vulnerability in cloud environments.
Two critical Remote Code Execution (RCE) vulnerabilities were recently patched in popular Spring Java libraries, and both have generated quite a bit of buzz:
CVE-2022-22965 (Spring Framework RCE via Data Binding on JDK version 9 or higher) –
This vulnerability affects Java software dependent on Spring Framework versions earlier than 5.2.19, and versions 5.3.0 to 5.3.17. Developers must update their software’s dependencies to Spring Framework versions 5.3.18 or 5.2.20, or apply any of multiple workarounds suggested by Spring .
Dubbed “Spring4Shell” (in the same vein a
Wiz
Addressing the Spring4Shell and CVE-2022-22963 RCE vulnerabilities in cloud environments | Wiz Blog
blogs_wiz·2022-04-01·CVSS 6.0
CVE-2022-22963 [MEDIUM] Addressing the Spring4Shell and CVE-2022-22963 RCE vulnerabilities in cloud environments | Wiz Blog
Updated April 13th, 2022 to include the latest available information about CVE-2022-22965, further explanation of dependencies in Spring Framework, and data about the prevalence of this vulnerability in cloud environments.
Two critical Remote Code Execution (RCE) vulnerabilities were recently patched in popular Spring Java libraries, and both have generated quite a bit of buzz:
CVE-2022-22965 (Spring Framework RCE via Data Binding on JDK version 9 or higher) –
- This vulnerability affects Java software dependent on Spring Framework versions earlier than 5.2.19, and versions 5.3.0 to 5.3.17. Developers must update their software’s dependencies to Spring Framework versions 5.3.18 or 5.2.20, or apply any of multiple workarounds suggested by Spring.
- Dubbed “Spring4Shell” (in the same vein
Talos
Threat Advisory: Spring4Shell
blogs_talos·2022-03-31·CVSS 6.0
CVE-2022-22965 [MEDIUM] Threat Advisory: Spring4Shell
## UPDATE, APRIL 4, 2022:
The Kenna Risk Score for CVE-2022-22965 is currently at maximum 100. This is an exceptionally rare score, of which only 415 out of 184,000 CVEs (or 0.22 percent) have achieved, reflecting the severity and potential effects of this vulnerability. To get a risk score this high means it is a widely deployed technology with a public exploit available, and we have seen proof of an ongoing active internet breach using the vulnerability.
Kenna Risk Scores are continually reevaluated and may shift over time. An outline of the current risk score is below:
Cisco Talos is releasing coverage to protect users against the exploitation of two remote code execution vulnerabilities in Spring Framework. CVE-2022-22963 is a medium-severity bug that affects Spring Cloud and CVE-20
Unit42
CVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated)
blogs_unit42·2022-03-31·CVSS 6.0
CVE-2022-22965 [MEDIUM] CVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated)
## Executive Summary
Recently, two vulnerabilities were announced within the Spring Framework, an open-source framework for building enterprise Java applications. On March 29, 2022, the Spring Cloud Expression Resource Access Vulnerability tracked in CVE-2022-22963 was patched with the release of Spring Cloud Function 3.1.7 and 3.2.3. Two days later on March 31, 2022, Spring released version 5.3.18 and 5.2.20 of Spring Framework to patch another more severe vulnerability tracked in CVE-2022-22965. The CVE-2022-22965 vulnerability allows an attacker unauthenticated remote code execution (RCE), which Unit 42 has observed being exploited in the wild. The exploitation of this vulnerability could result in a webshell being installed onto the compromised server that allows further command execu
Talos
Threat Advisory: Spring4Shell
blogs_talos·2022-03-31·CVSS 6.0
CVE-2022-22965 [MEDIUM] Threat Advisory: Spring4Shell
## Threat Advisory: Spring4Shell
## UPDATE, APRIL 4, 2022:
The Kenna Risk Score for CVE-2022-22965 is currently at maximum 100. This is an exceptionally rare score, of which only 415 out of 184,000 CVEs (or 0.22 percent) have achieved, reflecting the severity and potential effects of this vulnerability. To get a risk score this high means it is a widely deployed technology with a public exploit available, and we have seen proof of an ongoing active internet breach using the vulnerability.
Kenna Risk Scores are continually reevaluated and may shift over time. An outline of the current risk score is below:
Cisco Talos is releasing coverage to protect users against the exploitation of two remote code execution vulnerabilities in Spring Framework. CVE-2022-22963 is a medium-severity bug th
Unit42
CVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated)
blogs_unit42·2022-03-31·CVSS 9.8
CVE-2022-22965 [CRITICAL] CVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated)
Threat Research Center
High Profile Threats
Vulnerabilities
## CVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated)
Haozhe Zhang
Ken Hsu
Tao Yan
Qi Deng
Robert Falcone
Published: March 31, 2022
High Profile Threats
Vulnerabilities
CVE-2022-22963
CVE-2022-22965
Exploit in the wild
Remote Code Execution
SpringShell
## Executive Summary
Recently, two vulnerabilities were announced within the Spring Framework, an open-source framework for building enterprise Java applications. On March 29, 2022, the Spring Cloud Expression Resource Access Vulnerability tracked in CVE-2022-22963 was patched with the release of Spring Cloud Function 3.1.7 and 3.2.3. Two days later on March 31, 2022, Spring released version 5.3.18 and
Tenable
Spring4Shell (CVE-2022-22965) FAQ: Spring Framework Remote Code Execution Vulnerability
blogs_tenable·2022-03-30·CVSS 9.8
[CRITICAL] Spring4Shell (CVE-2022-22965) FAQ: Spring Framework Remote Code Execution Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2010-1622 SpringSource Spring Framework (x < 2.5.6.SEC02, 2.5.7.SR01, 3.0.3): Arbitrary Java code execution via an HTTP request containing a specially-crafted .jar file
bugzilla·2010-06-22·CVSS 6.0
CVE-2010-1622 [MEDIUM] CVE-2010-1622 SpringSource Spring Framework (x < 2.5.6.SEC02, 2.5.7.SR01, 3.0.3): Arbitrary Java code execution via an HTTP request containing a specially-crafted .jar file
CVE-2010-1622 SpringSource Spring Framework (x < 2.5.6.SEC02, 2.5.7.SR01, 3.0.3): Arbitrary Java code execution via an HTTP request containing a specially-crafted .jar file
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-1622 to
the following vulnerability:
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before
2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute
arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar:
followed by a URL of a crafted .jar file.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1622
[2] http://www.securityfocus.com/archive/1/511877
[3] http://www.exploit-db.com/exploits/13918
[4] http://www.springsource.com/security/cve-2010-1622
[5] http://www.securityfocus.com/b
http://geronimo.apache.org/2010/07/21/apache-geronimo-v216-released.htmlhttp://geronimo.apache.org/21x-security-report.htmlhttp://geronimo.apache.org/22x-security-report.htmlhttp://secunia.com/advisories/41016http://secunia.com/advisories/41025http://secunia.com/advisories/43087http://www.exploit-db.com/exploits/13918http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0175.htmlhttp://www.securityfocus.com/archive/1/511877http://www.securityfocus.com/bid/40954http://www.securitytracker.com/id/1033898http://www.springsource.com/security/cve-2010-1622http://www.vupen.com/english/advisories/2011/0237http://geronimo.apache.org/2010/07/21/apache-geronimo-v216-released.htmlhttp://geronimo.apache.org/21x-security-report.htmlhttp://geronimo.apache.org/22x-security-report.htmlhttp://secunia.com/advisories/41016http://secunia.com/advisories/41025http://secunia.com/advisories/43087http://www.exploit-db.com/exploits/13918http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0175.htmlhttp://www.securityfocus.com/archive/1/511877http://www.securityfocus.com/bid/40954http://www.securitytracker.com/id/1033898http://www.springsource.com/security/cve-2010-1622http://www.vupen.com/english/advisories/2011/0237
2010-06-21
Published