HomeVmwareCVE-2022-22965

CVE-2022-22965

CRITICAL
9.8CVSS
Published: 2022-04-01
Updated: 2025-10-30
AI Analysis

Description

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
network
Complexity
low
Privileges
none
User Action
none
Scope
unchanged
Confidentiality
high
Integrity
high
Availability
high
Weaknesses
CWE-94CWE-94

Metadata

Primary Vendor
VMWARE
Published
4/1/2022
Last Modified
10/30/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

vmware : spring_frameworkvmware : spring_frameworkcisco : cx_cloud_agentoracle : communications_cloud_native_core_automated_test_suiteoracle : communications_cloud_native_core_automated_test_suiteoracle : communications_cloud_native_core_consoleoracle : communications_cloud_native_core_consoleoracle : communications_cloud_native_core_network_exposure_functionoracle : communications_cloud_native_core_network_function_cloud_native_environmentoracle : communications_cloud_native_core_network_function_cloud_native_environmentoracle : communications_cloud_native_core_network_repository_functionoracle : communications_cloud_native_core_network_repository_functionoracle : communications_cloud_native_core_network_slice_selection_functionoracle : communications_cloud_native_core_network_slice_selection_functionoracle : communications_cloud_native_core_network_slice_selection_functionoracle : communications_cloud_native_core_policyoracle : communications_cloud_native_core_policyoracle : communications_cloud_native_core_security_edge_protection_proxyoracle : communications_cloud_native_core_security_edge_protection_proxyoracle : communications_cloud_native_core_unified_data_repositoryoracle : communications_cloud_native_core_unified_data_repositoryoracle : communications_policy_managementoracle : financial_services_analytical_applications_infrastructureoracle : financial_services_analytical_applications_infrastructureoracle : financial_services_behavior_detection_platformoracle : financial_services_behavior_detection_platformoracle : financial_services_behavior_detection_platformoracle : financial_services_enterprise_case_managementoracle : financial_services_enterprise_case_managementoracle : financial_services_enterprise_case_managementoracle : mysql_enterprise_monitororacle : product_lifecycle_analyticsoracle : retail_xstore_point_of_serviceoracle : retail_xstore_point_of_serviceoracle : sd-wan_edgeoracle : sd-wan_edgesiemens : operation_schedulersiemens : sipass_integratedsiemens : sipass_integratedsiemens : siveillance_identitysiemens : siveillance_identityveritas : access_applianceveritas : access_applianceveritas : access_applianceveritas : access_applianceveritas : access_applianceveritas : access_applianceveritas : flex_applianceveritas : flex_applianceveritas : flex_applianceveritas : flex_applianceveritas : flex_applianceveritas : netbackup_flex_scale_applianceveritas : netbackup_flex_scale_applianceveritas : netbackup_applianceveritas : netbackup_applianceveritas : netbackup_applianceveritas : netbackup_applianceveritas : netbackup_applianceveritas : netbackup_applianceveritas : netbackup_applianceveritas : netbackup_virtual_applianceveritas : netbackup_virtual_applianceveritas : netbackup_virtual_applianceveritas : netbackup_virtual_applianceveritas : netbackup_virtual_applianceveritas : netbackup_virtual_applianceveritas : netbackup_virtual_appliancesiemens : operation_schedulersiemens : simatic_speech_assistant_for_machinessiemens : sinec_network_management_systemsiemens : sipass_integratedsiemens : sipass_integratedsiemens : siveillance_identitysiemens : siveillance_identityoracle : commerce_platformoracle : communications_cloud_native_core_binding_support_functionoracle : communications_unified_inventory_managementoracle : communications_unified_inventory_managementoracle : communications_unified_inventory_managementoracle : retail_bulk_data_integrationoracle : retail_customer_management_and_segmentation_foundationoracle : retail_customer_management_and_segmentation_foundationoracle : retail_customer_management_and_segmentation_foundationoracle : retail_financial_integrationoracle : retail_financial_integrationoracle : retail_financial_integrationoracle : retail_financial_integrationoracle : retail_integration_busoracle : retail_integration_busoracle : retail_integration_busoracle : retail_integration_busoracle : retail_merchandising_systemoracle : retail_merchandising_systemoracle : weblogic_serveroracle : weblogic_serveroracle : weblogic_server

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief