Description
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
Published: 2022-04-01
Score: 9.8 Critical
EPSS: 94.4% High
KEV: Yes
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-36p3-wjmg-h94x Remote Code Execution in Spring Framework
Ubuntu USN Ubuntu USN USN-7165-1 Spring Framework vulnerability
History

Wed, 22 Oct 2025 00:30:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.94464}

epss

{'score': 0.94487}


Wed, 29 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2022-04-04'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 22 Nov 2024 12:00:00 +0000

Type Values Removed Values Added
References

Fri, 18 Oct 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle jdk
CPEs cpe:2.3:a:oracle:jdk:*:*:*:*:*:*:*:*
Vendors & Products Oracle jdk

Wed, 14 Aug 2024 01:00:00 +0000

Type Values Removed Values Added
References

Subscriptions

Cisco Cx Cloud Agent
Oracle Commerce Platform Communications Cloud Native Core Automated Test Suite Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Console Communications Cloud Native Core Network Exposure Function Communications Cloud Native Core Network Function Cloud Native Environment Communications Cloud Native Core Network Repository Function Communications Cloud Native Core Network Slice Selection Function Communications Cloud Native Core Policy Communications Cloud Native Core Security Edge Protection Proxy Communications Cloud Native Core Unified Data Repository Communications Policy Management Communications Unified Inventory Management Financial Services Analytical Applications Infrastructure Financial Services Behavior Detection Platform Financial Services Enterprise Case Management Jdk Mysql Enterprise Monitor Product Lifecycle Analytics Retail Bulk Data Integration Retail Customer Management And Segmentation Foundation Retail Financial Integration Retail Integration Bus Retail Merchandising System Retail Xstore Point Of Service Sd-wan Edge Weblogic Server
Redhat Amq Broker Camel Quarkus Integration Jboss Enterprise Bpms Platform Jboss Enterprise Brms Platform Jboss Fuse
Siemens Operation Scheduler Simatic Speech Assistant For Machines Sinec Network Management System Sipass Integrated Siveillance Identity
Veritas Access Appliance Flex Appliance Netbackup Appliance Netbackup Flex Scale Appliance Netbackup Virtual Appliance
Vmware Spring Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2025-10-21T23:15:42.792Z

Reserved: 2022-01-10T00:00:00.000Z

Link: CVE-2022-22965

cve-icon Vulnrichment

Updated: 2024-08-03T03:28:42.725Z

cve-icon NVD

Status : Analyzed

Published: 2022-04-01T23:15:13.870

Modified: 2025-10-30T19:56:43.110

Link: CVE-2022-22965

cve-icon Redhat

Severity : Important

Publid Date: 2022-03-30T00:00:00Z

Links: CVE-2022-22965 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses