← All CVEs

CVE-2022-22963

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-08-25Remediation due 2022-09-15

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

9.8
CVSS
99.9%
EPSS (exploit prob.)
100th
EPSS percentile
2022-04-01
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-94CWE-917

Affected products

VendorProductAffected versions
vmwarespring_cloud_function<= 3.1.6
vmwarespring_cloud_function>= 3.2.0, <= 3.2.2
oraclebanking_branch14.5
oraclebanking_cash_management14.5
oraclebanking_corporate_lending_process_management14.5
oraclebanking_credit_facilities_process_management14.5
oraclebanking_electronic_data_exchange_for_corporates14.5
oraclebanking_liquidity_management14.2
oraclebanking_liquidity_management14.5
oraclebanking_origination14.5
oraclebanking_supply_chain_finance14.5
oraclebanking_trade_finance_process_management14.5
oraclebanking_virtual_account_management14.5
oraclecommunications_cloud_native_core_automated_test_suite1.9.0
oraclecommunications_cloud_native_core_automated_test_suite22.1.0
oraclecommunications_cloud_native_core_console1.9.0
oraclecommunications_cloud_native_core_console22.1.0
oraclecommunications_cloud_native_core_network_exposure_function22.1.0
oraclecommunications_cloud_native_core_network_function_cloud_native_environment1.10.0
oraclecommunications_cloud_native_core_network_function_cloud_native_environment22.1.0
oraclecommunications_cloud_native_core_network_function_cloud_native_environment22.1.2
oraclecommunications_cloud_native_core_network_repository_function1.15.0
oraclecommunications_cloud_native_core_network_repository_function22.1.0
oraclecommunications_cloud_native_core_network_slice_selection_function1.8.0
oraclecommunications_cloud_native_core_network_slice_selection_function22.1.0
oraclecommunications_cloud_native_core_policy1.15.0
oraclecommunications_cloud_native_core_policy22.1.0
oraclecommunications_cloud_native_core_policy22.1.3
oraclecommunications_cloud_native_core_security_edge_protection_proxy1.7.0
oraclecommunications_cloud_native_core_security_edge_protection_proxy22.1.0
oraclecommunications_cloud_native_core_unified_data_repository1.15.0
oraclecommunications_cloud_native_core_unified_data_repository22.1.0
oraclecommunications_communications_policy_management12.6.0.0.0
oraclefinancial_services_analytical_applications_infrastructure8.1.1.0
oraclefinancial_services_analytical_applications_infrastructure8.1.2.0
oraclefinancial_services_behavior_detection_platform8.1.1.0
oraclefinancial_services_behavior_detection_platform8.1.1.1
oraclefinancial_services_behavior_detection_platform8.1.2.0
oraclefinancial_services_enterprise_case_management8.1.1.0
oraclefinancial_services_enterprise_case_management8.1.1.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-22963