cbcvebase.
CVE-2022-22965
published 2022-04-01

CVE-2022-22965: A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires…

PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-04-25
Exploited in the wild
EPSS
99.68%
99.9th percentile
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

Affected

108 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocx_cloud_agent< 2.1.02.1.0
debianlibspring-java
gxsoftwarexperiencentral<= 10.36.0
oraclecommerce_platform
oraclecommunications_cloud_native_core_automated_test_suite
oraclecommunications_cloud_native_core_automated_test_suite
oraclecommunications_cloud_native_core_binding_support_function
oraclecommunications_cloud_native_core_console
oraclecommunications_cloud_native_core_console
oraclecommunications_cloud_native_core_network_exposure_function
oraclecommunications_cloud_native_core_network_function_cloud_native_environment
oraclecommunications_cloud_native_core_network_function_cloud_native_environment
oraclecommunications_cloud_native_core_network_repository_function
oraclecommunications_cloud_native_core_network_repository_function
oraclecommunications_cloud_native_core_network_slice_selection_function
oraclecommunications_cloud_native_core_network_slice_selection_function
oraclecommunications_cloud_native_core_network_slice_selection_function
oraclecommunications_cloud_native_core_policy
oraclecommunications_cloud_native_core_policy
oraclecommunications_cloud_native_core_security_edge_protection_proxy
oraclecommunications_cloud_native_core_security_edge_protection_proxy
oraclecommunications_cloud_native_core_unified_data_repository
oraclecommunications_cloud_native_core_unified_data_repository
oraclecommunications_policy_management
oraclecommunications_unified_inventory_management

Detection & IOCsextracted from sources · hover to see the quote

hashe4973db44081591e9bff5117946defbef6041397e56164f485cf8ec57b1d8934
hash93fefc3e88ffb78abb36365fa5cf857c
hash59f1e69b68de4839c65b6e6d39ac7a272e2611ec1ed1bf73a4f455e2ca20eeaa
hashdf11b3105df8d7c70e7b501e210e3cc3
hash5616b94f1a40b49096e2f8f78d646891b45c649473a5b67b8beddac46ad398e1
hash3e10a74a7613d1cae4b9749d7ec93515
hash1a234656f81e870cdeb0e648a6b305a41452c405cca21124de26b54f79d55ad0
hash10f1561457242973e0fed724eec92f8c
hash12459a5e9afdb2dbff685c8c4e916bb15b34745d56ef5f778df99416d2749261
hash3e2dbdfa5e58cb43cca56a3e077d50bf
snort
Snort SIDs: 30790-30793, 59388, and 59416
  • Exploitation is limited to applications packaged as WAR files served by Apache Tomcat, GlassFish, or Payara; scope detection to those web container environments
  • Spring Boot executable JAR deployments are NOT vulnerable; focus detection resources on WAR-deployed Spring applications
  • The vulnerability is triggered via data binding with particular parameter types in spring-webmvc or spring-webflux; inspect HTTP request parameters for class loader manipulation patterns (e.g., class.module.classLoader references)
  • The vulnerability has been linked to Mirai botnet activity in addition to coinminer deployment; monitor for botnet C2 traffic from compromised Spring/Tomcat hosts
  • ·Only applications running on JDK 9 or higher are vulnerable; JDK 8 and below are not affected
  • ·The underlying bug is in spring-beans but is only currently triggerable via spring-webmvc or spring-webflux; applications not using these libraries are not exploitable by known methods

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_cisco9.8CRITICAL
vendor_debian9.8LOW
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.