← All CVEs

CVE-2022-22947

critical · 10Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-05-16Remediation due 2022-06-06

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.

10
CVSS
98.3%
EPSS (exploit prob.)
100th
EPSS percentile
2022-03-03
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-94CWE-917

Affected products

VendorProductAffected versions
vmwarespring_cloud_gateway< 3.0.7
vmwarespring_cloud_gateway3.1.0
oraclecommerce_guided_search11.3.2
oraclecommunications_cloud_native_core_binding_support_function1.11.0
oraclecommunications_cloud_native_core_binding_support_function22.1.3
oraclecommunications_cloud_native_core_console22.2.0
oraclecommunications_cloud_native_core_network_exposure_function22.1.0
oraclecommunications_cloud_native_core_network_function_cloud_native_environment1.10.0
oraclecommunications_cloud_native_core_network_repository_function1.15.0
oraclecommunications_cloud_native_core_network_repository_function1.15.1
oraclecommunications_cloud_native_core_network_repository_function22.1.2
oraclecommunications_cloud_native_core_network_repository_function22.2.0
oraclecommunications_cloud_native_core_network_slice_selection_function1.8.0
oraclecommunications_cloud_native_core_network_slice_selection_function22.1.0
oraclecommunications_cloud_native_core_security_edge_protection_proxy22.1.1
oraclecommunications_cloud_native_core_service_communication_proxy1.15.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-22947