Fiche vulnérabilité
CVE-2022-22963 : faille exploitée vmware spring cloud function (CVSS 9.8)
Description
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Oui, inscrite au catalogue CISA KEV
- Publication
- 1 avr. 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- vmware spring cloud function
- oracle banking branch
- oracle banking cash management
- oracle banking corporate lending process management
- oracle banking credit facilities process management
- oracle banking electronic data exchange for corporates
- oracle banking liquidity management
- oracle banking origination
- oracle banking supply chain finance
- oracle banking trade finance process management
- oracle banking virtual account management
- oracle communications cloud native core automated test suite
- oracle communications cloud native core console
- oracle communications cloud native core network exposure function
- oracle communications cloud native core network function cloud native environment
- oracle communications cloud native core network repository function
- oracle communications cloud native core network slice selection function
- oracle communications cloud native core policy
- oracle communications cloud native core security edge protection proxy
- oracle communications cloud native core unified data repository
Correctif et mesures
Apply updates per vendor instructions.
Références
- Fiche CVE-2022-22963 sur le NVD (NIST)
- packetstormsecurity.com/files/173430/Spring…
- psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005
- tanzu.vmware.com/security/cve-2022-22963
- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/…
- oracle.com/security-alerts/cpuapr2022.html
- oracle.com/security-alerts/cpujul2022.html
- cisa.gov/known-exploited-vulnerabilities-catalog