cbcvebase.
CVE-2022-22963
published 2022-04-01

CVE-2022-22963: In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a…

PriorityP197critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-09-15
Exploited in the wild
EPSS
99.94%
100.0th percentile
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

Affected

71 ranges· showing 25
VendorProductVersion rangeFixed in
oraclebanking_branch
oraclebanking_cash_management
oraclebanking_corporate_lending_process_management
oraclebanking_credit_facilities_process_management
oraclebanking_electronic_data_exchange_for_corporates
oraclebanking_liquidity_management
oraclebanking_liquidity_management
oraclebanking_origination
oraclebanking_supply_chain_finance
oraclebanking_trade_finance_process_management
oraclebanking_virtual_account_management
oraclecommunications_cloud_native_core_automated_test_suite
oraclecommunications_cloud_native_core_automated_test_suite
oraclecommunications_cloud_native_core_console
oraclecommunications_cloud_native_core_console
oraclecommunications_cloud_native_core_network_exposure_function
oraclecommunications_cloud_native_core_network_function_cloud_native_environment
oraclecommunications_cloud_native_core_network_function_cloud_native_environment
oraclecommunications_cloud_native_core_network_function_cloud_native_environment
oraclecommunications_cloud_native_core_network_repository_function
oraclecommunications_cloud_native_core_network_repository_function
oraclecommunications_cloud_native_core_network_slice_selection_function
oraclecommunications_cloud_native_core_network_slice_selection_function
oraclecommunications_cloud_native_core_policy
oraclecommunications_cloud_native_core_policy

Detection & IOCsextracted from sources · hover to see the quote

snort
Snort SIDs: 30790-30793, 59388, and 59416
  • CVE-2022-22963 is only exploitable in applications using Spring Cloud Function routing functionality; focus detection on endpoints that process routing expressions
  • The vulnerability is remotely exploitable without authentication via a specially crafted HTTP request; alert on unauthenticated POST requests to Spring Cloud Function endpoints with routing-expression headers
  • CVE-2022-22963 affects Spring Cloud Function versions 3.1.6, 3.2.2 and older; detect vulnerable version strings in deployed JAR manifests or dependency trees
  • ·CVE-2022-22963 is only exploitable when the Spring Cloud Function application uses routing functionality; applications not using routing are not affected
  • ·Most software dependent on the Spring Cloud Function library runs on short-lived FaaS/Serverless instances, limiting practical exploitation impact in many environments
  • ·The SpEL payload is evaluated by SimpleEvaluationContext; detection rules should account for obfuscated or variant SpEL expressions targeting the routing-expression header

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_cisco9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.