CVE-2022-22950
published 2022-04-01CVE-2022-22950: n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may…
PriorityP342medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
35.83%
98.3th percentile
n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libspring-java | — | — |
| vmware | spring_framework | < 5.2.20 | 5.2.20 |
| vmware | spring_framework | — | — |
| vmware | spring_framework | >= 5.3.0 < 5.3.17 | 5.3.17 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Security Management (Spring Framework) — CVE-2022-22950
vendor_oracle·2023-07-15·CVSS 6.5
CVE-2022-22950 [MEDIUM] Oracle Oracle Enterprise Manager Risk Matrix: Security Management (Spring Framework) — CVE-2022-22950
Oracle Oracle Enterprise Manager Risk Matrix: Security Management (Spring Framework) vulnerability
CVE: CVE-2022-22950
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
CISA ICS
Hitachi Energy Lumada Asset Performance Management Prognostic Model Executor Service
cisa_ics·2022-10-13·CVSS 6.5
[MEDIUM] Hitachi Energy Lumada Asset Performance Management Prognostic Model Executor Service
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy Lumada Asset Performance Management Prognostic Model Executor Service
Last RevisedOctober 13, 2022
Alert CodeICSA-22-286-05
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/public exploits are available
- Vendor: Hitachi Energy
- Equipment: Lumada Asset Performance Manager (APM)
- Vulnerabilities: Allocation of Resources Without Limits or Throttling, Code injection
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could crash the Prognostic Model Executor and could allow remote code execution.
## 3. TECHNICAL DETA
Red Hat
spring-expression: Denial of service via specially crafted SpEL expression
vendor_redhat·2022-03-28·CVSS 6.5
CVE-2022-22950 [MEDIUM] CWE-770 spring-expression: Denial of service via specially crafted SpEL expression
spring-expression: Denial of service via specially crafted SpEL expression
n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.
A flaw was found in the Spring Framework. This flaw allows an attacker to craft a special Spring Expression, causing a denial of service.
Package: spring-expression (A-MQ Clients 2) - Not affected
Package: spring-expression (Logging Subsystem for Red Hat OpenShift) - Will not fix
Package: spring-expression (Red Hat AMQ Broker 7) - Not affected
Package: spring-expression (Red Hat build of Quarkus) - Not affected
Package: spring-expression (Red Hat Data Grid 8) - Will not fix
Package: spring-expression (Red Hat Integrat
Debian
CVE-2022-22950: libspring-java - n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is...
vendor_debian·2022·CVSS 6.5
CVE-2022-22950 [MEDIUM] CVE-2022-22950: libspring-java - n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is...
n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
OSV
Allocation of Resources Without Limits or Throttling in Spring Framework
osv·2022-04-03
CVE-2022-22950 [MEDIUM] Allocation of Resources Without Limits or Throttling in Spring Framework
Allocation of Resources Without Limits or Throttling in Spring Framework
In Spring Framework versions 5.3.0 - 5.3.16, 5.2.0.RELEASE - 5.2.19.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.
GHSA
Allocation of Resources Without Limits or Throttling in Spring Framework
ghsa·2022-04-03
CVE-2022-22950 [MEDIUM] CWE-770 Allocation of Resources Without Limits or Throttling in Spring Framework
Allocation of Resources Without Limits or Throttling in Spring Framework
In Spring Framework versions 5.3.0 - 5.3.16, 5.2.0.RELEASE - 5.2.19.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.
OSV
CVE-2022-22950: n Spring Framework versions 5
osv·2022-04-01·CVSS 6.5
CVE-2022-22950 [MEDIUM] CVE-2022-22950: n Spring Framework versions 5
n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-04-01
Published