CVE-2022-22971
published 2022-05-12CVE-2022-22971: In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a…
PriorityP434medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
3.13%
86.4th percentile
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libspring-java | — | — |
| oracle | financial_services_crime_and_compliance_management_studio | — | — |
| oracle | financial_services_crime_and_compliance_management_studio | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | 5.2.0 – 5.2.21 | — |
| vmware | spring_framework | 5.3.0 – 5.3.19 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Infrastructure Management (Spring Framework) — CVE-2022-22971
vendor_oracle·2023-07-15·CVSS 6.5
CVE-2022-22971 [MEDIUM] Oracle Oracle Enterprise Manager Risk Matrix: Infrastructure Management (Spring Framework) — CVE-2022-22971
Oracle Oracle Enterprise Manager Risk Matrix: Infrastructure Management (Spring Framework) vulnerability
CVE: CVE-2022-22971
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Base (Spring Framework) — CVE-2022-22971
vendor_oracle·2023-04-15·CVSS 6.5
CVE-2022-22971 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Base (Spring Framework) — CVE-2022-22971
Oracle Oracle Financial Services Applications Risk Matrix: Base (Spring Framework) vulnerability
CVE: CVE-2022-22971
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Security (Spring Framework) — CVE-2022-22971
vendor_oracle·2023-01-15·CVSS 6.5
CVE-2022-22971 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Security (Spring Framework) — CVE-2022-22971
Oracle Oracle Communications Applications Risk Matrix: Security (Spring Framework) vulnerability
CVE: CVE-2022-22971
CVSS: 6.5
Protocol: TCP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Oracle
Oracle Oracle Commerce Risk Matrix: Endeca Integration (Spring Framework) — CVE-2022-22971
vendor_oracle·2022-10-15·CVSS 6.5
CVE-2022-22971 [MEDIUM] Oracle Oracle Commerce Risk Matrix: Endeca Integration (Spring Framework) — CVE-2022-22971
Oracle Oracle Commerce Risk Matrix: Endeca Integration (Spring Framework) vulnerability
CVE: CVE-2022-22971
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Studio (Spring Framework) — CVE-2022-22971
vendor_oracle·2022-07-15·CVSS 6.5
CVE-2022-22971 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Studio (Spring Framework) — CVE-2022-22971
Oracle Oracle Financial Services Applications Risk Matrix: Studio (Spring Framework) vulnerability
CVE: CVE-2022-22971
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Red Hat
springframework: DoS with STOMP over WebSocket
vendor_redhat·2022-05-11·CVSS 6.5
CVE-2022-22971 [MEDIUM] CWE-770 springframework: DoS with STOMP over WebSocket
springframework: DoS with STOMP over WebSocket
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
A flaw was found in Spring Framework Applications. Applications that use STOMP over the WebSocket endpoint are vulnerable to a denial of service attack caused by an authenticated user.
Package: springframework (A-MQ Clients 2) - Not affected
Package: springframework (Red Hat build of Quarkus) - Not affected
Package: springframework (Red Hat Data Grid 8) - Not affected
Package: springframework (Red Hat Decision Manager 7) - Fix deferred
Package: springframework (Red Hat Integration Camel K 1) - Not affected
Package: springframework (Re
Debian
CVE-2022-22971: libspring-java - In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported vers...
vendor_debian·2022·CVSS 6.5
CVE-2022-22971 [MEDIUM] CVE-2022-22971: libspring-java - In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported vers...
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
Allocation of Resources Without Limits or Throttling in Spring Framework
ghsa·2022-05-13
CVE-2022-22971 [MEDIUM] CWE-770 Allocation of Resources Without Limits or Throttling in Spring Framework
Allocation of Resources Without Limits or Throttling in Spring Framework
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
OSV
Allocation of Resources Without Limits or Throttling in Spring Framework
osv·2022-05-13
CVE-2022-22971 [MEDIUM] Allocation of Resources Without Limits or Throttling in Spring Framework
Allocation of Resources Without Limits or Throttling in Spring Framework
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
OSV
CVE-2022-22971: In spring framework versions prior to 5
osv·2022-05-12·CVSS 6.5
CVE-2022-22971 [MEDIUM] CVE-2022-22971: In spring framework versions prior to 5
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://security.netapp.com/advisory/ntap-20220616-0003/https://tanzu.vmware.com/security/cve-2022-22971https://www.oracle.com/security-alerts/cpujul2022.htmlhttps://security.netapp.com/advisory/ntap-20220616-0003/https://tanzu.vmware.com/security/cve-2022-22971https://www.oracle.com/security-alerts/cpujul2022.html
2022-05-12
Published