CVE-2022-22946
published 2022-03-04CVE-2022-22946: In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be…
PriorityP430medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
EPSS
4.85%
91.0th percentile
In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | commerce_guided_search | — | — |
| oracle | communications_cloud_native_core_binding_support_function | — | — |
| oracle | communications_cloud_native_core_console | — | — |
| oracle | communications_cloud_native_core_network_repository_function | — | — |
| oracle | communications_cloud_native_core_network_repository_function | — | — |
| oracle | communications_cloud_native_core_security_edge_protection_proxy | — | — |
| vmware | spring_cloud_gateway | — | — |
| vmware | spring_cloud_gateway | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
vendor_oracle7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-28g5-j6gh-p2vw: In spring cloud gateway versions prior to 3
ghsa_unreviewed·2022-03-05
CVE-2022-22946 [MEDIUM] CWE-295 GHSA-28g5-j6gh-p2vw: In spring cloud gateway versions prior to 3
In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates.
Oracle
Oracle Oracle Essbase Risk Matrix: Build (cURL) — CVE-2021-22946
vendor_oracle·2022-10-15·CVSS 7.5
CVE-2021-22946 [HIGH] Oracle Oracle Essbase Risk Matrix: Build (cURL) — CVE-2021-22946
Oracle Oracle Essbase Risk Matrix: Build (cURL) vulnerability
CVE: CVE-2021-22946
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Commerce Risk Matrix: Framework, Experience Manager (cURL) — CVE-2021-22946
vendor_oracle·2022-07-15·CVSS 7.5
CVE-2021-22946 [HIGH] Oracle Oracle Commerce Risk Matrix: Framework, Experience Manager (cURL) — CVE-2021-22946
Oracle Oracle Commerce Risk Matrix: Framework, Experience Manager (cURL) vulnerability
CVE: CVE-2021-22946
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Communications Risk Matrix: CNC BSF (cURL) — CVE-2021-22946
vendor_oracle·2022-04-15·CVSS 7.5
CVE-2021-22946 [HIGH] Oracle Oracle Communications Risk Matrix: CNC BSF (cURL) — CVE-2021-22946
Oracle Oracle Communications Risk Matrix: CNC BSF (cURL) vulnerability
CVE: CVE-2021-22946
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle MySQL Risk Matrix: Server: Compiling (cURL) — CVE-2021-22946
vendor_oracle·2022-01-15·CVSS 7.5
CVE-2021-22946 [HIGH] Oracle Oracle MySQL Risk Matrix: Server: Compiling (cURL) — CVE-2021-22946
Oracle Oracle MySQL Risk Matrix: Server: Compiling (cURL) vulnerability
CVE: CVE-2021-22946
CVSS: 7.5
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-03-04
Published