CVE-2022-22965

Exp

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

Published: 2022-04-01 Last update: 2025-10-30 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2022-22965 is rated Critical Active Threat (99.2/100): CVSS Critical severity, with high exploitation likelihood (EPSS 94.43%, 100th percentile). Core evidence: CISA KEV confirms active exploitation (added 2022-04-04) affecting VMware / Spring Framework. a weakness (CWE-94) Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

CISA KEV Record for CVE-2022-22965

Name: Spring Framework JDK 9+ Remote Code Execution Vulnerability · CISA KEV detail

Exploit added: 2022-04-04

Action due: 2022-04-25

Required action: Apply updates per vendor instructions.

Public exploit references (Exploit-DB) for CVE-2022-22965

EDB-ID Source Kind Published Link
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2022-22965

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-05-25 94.46% 94.43% -0.03%
2 2026-05-22 94.43% 94.46% +0.03%
3 2026-03-22 94.43%

Full EPSS history (27 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2022-22965

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
9.8 3.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.9 5.9 [email protected]
9.8 3.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.9 5.9 134c704f-9b21-4f2e-91b3-4a467353bcc0
7.5 2.0 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
10.0 6.4 [email protected]

Weakness enumeration for CVE-2022-22965

GitHub Security Advisory for CVE-2022-22965

GHSA-36p3-wjmg-h94x · Severity: critical · Ecosystem: maven — Remote Code Execution in Spring Framework

OS Trackers for CVE-2022-22965

vendor priority summary link
debian unimportant CVE-2022-22965 unimportant priority: Debian including 1 source packages (libspring-java), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 5. https://security-tracker.debian.org/tracker/CVE-2022-22965
redhat high https://access.redhat.com/security/cve/CVE-2022-22965
ubuntu high CVE-2022-22965 high priority: Ubuntu including 1 source packages (libspring-java), 14 status rows across 14 suites (bionic, focal, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): released 8, ignored 4, not-affected 2. https://ubuntu.com/security/CVE-2022-22965

Affected software / configurations for CVE-2022-22965

Vendor Product Version Raw CPE
vmware spring_framework < 5.2.20 cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*
vmware spring_framework >= 5.3.0, < 5.3.18 cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*
cisco cx_cloud_agent < 2.1.0 cpe:2.3:a:cisco:cx_cloud_agent:*:*:*:*:*:*:*:*
oracle communications_cloud_native_core_automated_test_suite 1.9.0 cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.9.0:*:*:*:*:*:*:*
oracle communications_cloud_native_core_automated_test_suite 22.1.0 cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:22.1.0:*:*:*:*:*:*:*
oracle communications_cloud_native_core_console 1.9.0 cpe:2.3:a:oracle:communications_cloud_native_core_console:1.9.0:*:*:*:*:*:*:*
oracle communications_cloud_native_core_console 22.1.0 cpe:2.3:a:oracle:communications_cloud_native_core_console:22.1.0:*:*:*:*:*:*:*
oracle communications_cloud_native_core_network_exposure_function 22.1.0 cpe:2.3:a:oracle:communications_cloud_native_core_network_exposure_function:22.1.0:*:*:*:*:*:*:*
oracle communications_cloud_native_core_network_function_cloud_native_environment 1.10.0 cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:1.10.0:*:*:*:*:*:*:*
oracle communications_cloud_native_core_network_function_cloud_native_environment 22.1.0 cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:22.1.0:*:*:*:*:*:*:*
oracle communications_cloud_native_core_network_repository_function 1.15.0 cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.15.0:*:*:*:*:*:*:*
oracle communications_cloud_native_core_network_repository_function 22.1.0 cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:22.1.0:*:*:*:*:*:*:*
oracle communications_cloud_native_core_network_slice_selection_function 1.8.0 cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.8.0:*:*:*:*:*:*:*
oracle communications_cloud_native_core_network_slice_selection_function 1.15.0 cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.15.0:*:*:*:*:*:*:*
oracle communications_cloud_native_core_network_slice_selection_function 22.1.0 cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:22.1.0:*:*:*:*:*:*:*
oracle communications_cloud_native_core_policy 1.15.0 cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.15.0:*:*:*:*:*:*:*
oracle communications_cloud_native_core_policy 22.1.0 cpe:2.3:a:oracle:communications_cloud_native_core_policy:22.1.0:*:*:*:*:*:*:*
oracle communications_cloud_native_core_security_edge_protection_proxy 1.7.0 cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:1.7.0:*:*:*:*:*:*:*
oracle communications_cloud_native_core_security_edge_protection_proxy 22.1.0 cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:22.1.0:*:*:*:*:*:*:*
oracle communications_cloud_native_core_unified_data_repository 1.15.0 cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:1.15.0:*:*:*:*:*:*:*
oracle communications_cloud_native_core_unified_data_repository 22.1.0 cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:22.1.0:*:*:*:*:*:*:*
oracle communications_policy_management 12.6.0.0.0 cpe:2.3:a:oracle:communications_policy_management:12.6.0.0.0:*:*:*:*:*:*:*
oracle financial_services_analytical_applications_infrastructure 8.1.1 cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.1:*:*:*:*:*:*:*
oracle financial_services_analytical_applications_infrastructure 8.1.2.0 cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.2.0:*:*:*:*:*:*:*
oracle financial_services_behavior_detection_platform 8.1.1.0 cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.1.0:*:*:*:*:*:*:*
oracle financial_services_behavior_detection_platform 8.1.1.1 cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.1.1:*:*:*:*:*:*:*
oracle financial_services_behavior_detection_platform 8.1.2.0 cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.2.0:*:*:*:*:*:*:*
oracle financial_services_enterprise_case_management 8.1.1.0 cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.1.0:*:*:*:*:*:*:*
oracle financial_services_enterprise_case_management 8.1.1.1 cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.1.1:*:*:*:*:*:*:*
oracle financial_services_enterprise_case_management 8.1.2.0 cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.2.0:*:*:*:*:*:*:*
oracle mysql_enterprise_monitor < 8.0.29 cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*
oracle product_lifecycle_analytics 3.6.1 cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:*
oracle retail_xstore_point_of_service 20.0.1 cpe:2.3:a:oracle:retail_xstore_point_of_service:20.0.1:*:*:*:*:*:*:*
oracle retail_xstore_point_of_service 21.0.0 cpe:2.3:a:oracle:retail_xstore_point_of_service:21.0.0:*:*:*:*:*:*:*
oracle sd-wan_edge 9.0 cpe:2.3:a:oracle:sd-wan_edge:9.0:*:*:*:*:*:*:*
oracle sd-wan_edge 9.1 cpe:2.3:a:oracle:sd-wan_edge:9.1:*:*:*:*:*:*:*
siemens operation_scheduler < 2.0.4 cpe:2.3:a:siemens:operation_scheduler:*:*:*:*:*:*:*:*
siemens sipass_integrated 2.80 cpe:2.3:a:siemens:sipass_integrated:2.80:*:*:*:*:*:*:*
siemens sipass_integrated 2.85 cpe:2.3:a:siemens:sipass_integrated:2.85:*:*:*:*:*:*:*
siemens siveillance_identity 1.5 cpe:2.3:a:siemens:siveillance_identity:1.5:*:*:*:*:*:*:*
siemens siveillance_identity 1.6 cpe:2.3:a:siemens:siveillance_identity:1.6:*:*:*:*:*:*:*
veritas access_appliance 7.4.3 cpe:2.3:a:veritas:access_appliance:7.4.3:*:*:*:*:*:*:*
veritas access_appliance 7.4.3.100 cpe:2.3:a:veritas:access_appliance:7.4.3.100:*:*:*:*:*:*:*
veritas access_appliance 7.4.3.200 cpe:2.3:a:veritas:access_appliance:7.4.3.200:*:*:*:*:*:*:*
veritas flex_appliance 1.3 cpe:2.3:a:veritas:flex_appliance:1.3:*:*:*:*:*:*:*
veritas flex_appliance 2.0 cpe:2.3:a:veritas:flex_appliance:2.0:*:*:*:*:*:*:*
veritas flex_appliance 2.0.1 cpe:2.3:a:veritas:flex_appliance:2.0.1:*:*:*:*:*:*:*
veritas flex_appliance 2.0.2 cpe:2.3:a:veritas:flex_appliance:2.0.2:*:*:*:*:*:*:*
veritas flex_appliance 2.1 cpe:2.3:a:veritas:flex_appliance:2.1:*:*:*:*:*:*:*
veritas netbackup_flex_scale_appliance 2.1 cpe:2.3:a:veritas:netbackup_flex_scale_appliance:2.1:*:*:*:*:*:*:*
veritas netbackup_flex_scale_appliance 3.0 cpe:2.3:a:veritas:netbackup_flex_scale_appliance:3.0:*:*:*:*:*:*:*
veritas netbackup_appliance 4.0 cpe:2.3:h:veritas:netbackup_appliance:4.0:*:*:*:*:*:*:*
veritas netbackup_appliance 4.0.0.1 cpe:2.3:h:veritas:netbackup_appliance:4.0.0.1:maintenance_release1:*:*:*:*:*:*
veritas netbackup_appliance 4.0.0.1 cpe:2.3:h:veritas:netbackup_appliance:4.0.0.1:maintenance_release2:*:*:*:*:*:*
veritas netbackup_appliance 4.0.0.1 cpe:2.3:h:veritas:netbackup_appliance:4.0.0.1:maintenance_release3:*:*:*:*:*:*
veritas netbackup_appliance 4.1 cpe:2.3:h:veritas:netbackup_appliance:4.1:*:*:*:*:*:*:*
veritas netbackup_appliance 4.1.0.1 cpe:2.3:h:veritas:netbackup_appliance:4.1.0.1:maintenance_release1:*:*:*:*:*:*
veritas netbackup_appliance 4.1.0.1 cpe:2.3:h:veritas:netbackup_appliance:4.1.0.1:maintenance_release2:*:*:*:*:*:*
veritas netbackup_virtual_appliance 4.0 cpe:2.3:h:veritas:netbackup_virtual_appliance:4.0:*:*:*:*:*:*:*
veritas netbackup_virtual_appliance 4.0.0.1 cpe:2.3:h:veritas:netbackup_virtual_appliance:4.0.0.1:maintenance_release1:*:*:*:*:*:*
veritas netbackup_virtual_appliance 4.0.0.1 cpe:2.3:h:veritas:netbackup_virtual_appliance:4.0.0.1:maintenance_release2:*:*:*:*:*:*
veritas netbackup_virtual_appliance 4.0.0.1 cpe:2.3:h:veritas:netbackup_virtual_appliance:4.0.0.1:maintenance_release3:*:*:*:*:*:*
veritas netbackup_virtual_appliance 4.1 cpe:2.3:h:veritas:netbackup_virtual_appliance:4.1:*:*:*:*:*:*:*
veritas netbackup_virtual_appliance 4.1.0.1 cpe:2.3:h:veritas:netbackup_virtual_appliance:4.1.0.1:maintenance_release1:*:*:*:*:*:*
veritas netbackup_virtual_appliance 4.1.0.1 cpe:2.3:h:veritas:netbackup_virtual_appliance:4.1.0.1:maintenance_release2:*:*:*:*:*:*
siemens simatic_speech_assistant_for_machines < 1.2.1 cpe:2.3:a:siemens:simatic_speech_assistant_for_machines:*:*:*:*:*:*:*:*
siemens sinec_network_management_system < 1.0.3 cpe:2.3:a:siemens:sinec_network_management_system:*:*:*:*:*:*:*:*
oracle commerce_platform 11.3.2 cpe:2.3:a:oracle:commerce_platform:11.3.2:*:*:*:*:*:*:*
oracle communications_cloud_native_core_binding_support_function 22.1.3 cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:22.1.3:*:*:*:*:*:*:*
oracle communications_unified_inventory_management 7.4.1 cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.1:*:*:*:*:*:*:*
oracle communications_unified_inventory_management 7.4.2 cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.2:*:*:*:*:*:*:*
oracle communications_unified_inventory_management 7.5.0 cpe:2.3:a:oracle:communications_unified_inventory_management:7.5.0:*:*:*:*:*:*:*
oracle retail_bulk_data_integration 16.0.3 cpe:2.3:a:oracle:retail_bulk_data_integration:16.0.3:*:*:*:*:*:*:*
oracle retail_customer_management_and_segmentation_foundation 17.0 cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:17.0:*:*:*:*:*:*:*
oracle retail_customer_management_and_segmentation_foundation 18.0 cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:18.0:*:*:*:*:*:*:*
oracle retail_customer_management_and_segmentation_foundation 19.0 cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:19.0:*:*:*:*:*:*:*
oracle retail_financial_integration 14.1.3.2 cpe:2.3:a:oracle:retail_financial_integration:14.1.3.2:*:*:*:*:*:*:*
oracle retail_financial_integration 15.0.3.1 cpe:2.3:a:oracle:retail_financial_integration:15.0.3.1:*:*:*:*:*:*:*
oracle retail_financial_integration 16.0.3 cpe:2.3:a:oracle:retail_financial_integration:16.0.3:*:*:*:*:*:*:*
oracle retail_financial_integration 19.0.1 cpe:2.3:a:oracle:retail_financial_integration:19.0.1:*:*:*:*:*:*:*

References for CVE-2022-22965

URL Tags
http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/167011/Spring4Shell-Spring-Framework-Class-Property-Remote-Code-Execution.html Third Party Advisory VDB Entry
https://cert-portal.siemens.com/productcert/pdf/ssa-254054.pdf Patch Third Party Advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005 Third Party Advisory
https://tanzu.vmware.com/security/cve-2022-22965 Mitigation Vendor Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67 Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html Patch Third Party Advisory
https://www.kb.cert.org/vuls/id/970766 US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22965 US Government Resource
cvelogic Threat Intelligence