First published: Fri Apr 01 2022(Updated: )
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
Credit: security@vmware.com security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Spring Framework | <5.2.20 | |
VMware Spring Framework | >=5.3.0<5.3.18 | |
Cisco CX Cloud Agent | <2.1.0 | |
Oracle Communications Cloud Native Core Automated Test Suite | =1.9.0 | |
Oracle Communications Cloud Native Core Automated Test Suite | =22.1.0 | |
Oracle Communications Cloud Native Core Console | =1.9.0 | |
Oracle Communications Cloud Native Core Console | =22.1.0 | |
Oracle Communications Cloud Native Core Network Exposure Function | =22.1.0 | |
Oracle Communications Cloud Native Core Network Function Cloud Native Environment | =1.10.0 | |
Oracle Communications Cloud Native Core Network Function Cloud Native Environment | =22.1.0 | |
Oracle Communications Cloud Native Core Network Repository Function | =1.15.0 | |
Oracle Communications Cloud Native Core Network Repository Function | =22.1.0 | |
Oracle Communications Cloud Native Core Network Slice Selection Function | =1.8.0 | |
Oracle Communications Cloud Native Core Network Slice Selection Function | =1.15.0 | |
Oracle Communications Cloud Native Core Network Slice Selection Function | =22.1.0 | |
Oracle Communications Cloud Native Core Policy | =1.15.0 | |
Oracle Communications Cloud Native Core Policy | =22.1.0 | |
Oracle Communications Cloud Native Core Security Edge Protection Proxy | =1.7.0 | |
Oracle Communications Cloud Native Core Security Edge Protection Proxy | =22.1.0 | |
Oracle Communications Cloud Native Core Unified Data Repository | =1.15.0 | |
Oracle Communications Cloud Native Core Unified Data Repository | =22.1.0 | |
Oracle Communications Policy Management | =12.6.0.0.0 | |
Oracle Financial Services Analytical Applications Infrastructure | =8.1.1 | |
Oracle Financial Services Analytical Applications Infrastructure | =8.1.2.0 | |
Oracle Financial Services Behavior Detection Platform | =8.1.1.0 | |
Oracle Financial Services Behavior Detection Platform | =8.1.1.1 | |
Oracle Financial Services Behavior Detection Platform | =8.1.2.0 | |
Oracle Financial Services Enterprise Case Management | =8.1.1.0 | |
Oracle Financial Services Enterprise Case Management | =8.1.1.1 | |
Oracle Financial Services Enterprise Case Management | =8.1.2.0 | |
Oracle Mysql Enterprise Monitor | <8.0.29 | |
Oracle Product Lifecycle Analytics | =3.6.1 | |
Oracle Retail Xstore Point of Service | =20.0.1 | |
Oracle Retail Xstore Point of Service | =21.0.0 | |
Oracle SD-WAN Edge | =9.0 | |
Oracle SD-WAN Edge | =9.1 | |
Siemens Operation Scheduler | <2.0.4 | |
Siemens SiPass integrated | =2.80 | |
Siemens SiPass integrated | =2.85 | |
Siemens Siveillance Identity | =1.5 | |
Siemens Siveillance Identity | =1.6 | |
Veritas Access Appliance | =7.4.3 | |
Veritas Access Appliance | =7.4.3.100 | |
Veritas Access Appliance | =7.4.3.200 | |
Veritas Flex Appliance | =1.3 | |
Veritas Flex Appliance | =2.0 | |
Veritas Flex Appliance | =2.0.1 | |
Veritas Flex Appliance | =2.0.2 | |
Veritas Flex Appliance | =2.1 | |
Veritas Netbackup Flex Scale Appliance | =2.1 | |
Veritas Netbackup Flex Scale Appliance | =3.0 | |
Veritas NetBackup Appliance | =4.0 | |
Veritas NetBackup Appliance | =4.0.0.1-maintenance_release1 | |
Veritas NetBackup Appliance | =4.0.0.1-maintenance_release2 | |
Veritas NetBackup Appliance | =4.0.0.1-maintenance_release3 | |
Veritas NetBackup Appliance | =4.1 | |
Veritas NetBackup Appliance | =4.1.0.1-maintenance_release1 | |
Veritas NetBackup Appliance | =4.1.0.1-maintenance_release2 | |
Veritas Netbackup Virtual Appliance | =4.0 | |
Veritas Netbackup Virtual Appliance | =4.0.0.1-maintenance_release1 | |
Veritas Netbackup Virtual Appliance | =4.0.0.1-maintenance_release2 | |
Veritas Netbackup Virtual Appliance | =4.0.0.1-maintenance_release3 | |
Veritas Netbackup Virtual Appliance | =4.1 | |
Veritas Netbackup Virtual Appliance | =4.1.0.1-maintenance_release1 | |
Veritas Netbackup Virtual Appliance | =4.1.0.1-maintenance_release2 | |
Siemens Simatic Speech Assistant For Machines | <1.2.1 | |
Siemens Sinec Network Management System | <1.0.3 | |
Oracle Commerce Platform | =11.3.2 | |
Oracle Communications Cloud Native Core Binding Support Function | =22.1.3 | |
Oracle Communications Unified Inventory Management | =7.4.1 | |
Oracle Communications Unified Inventory Management | =7.4.2 | |
Oracle Communications Unified Inventory Management | =7.5.0 | |
Oracle Retail Bulk Data Integration | =16.0.3 | |
Oracle Retail Customer Management and Segmentation Foundation | =17.0 | |
Oracle Retail Customer Management and Segmentation Foundation | =18.0 | |
Oracle Retail Customer Management and Segmentation Foundation | =19.0 | |
Oracle Retail Financial Integration | =14.1.3.2 | |
Oracle Retail Financial Integration | =15.0.3.1 | |
Oracle Retail Financial Integration | =16.0.3 | |
Oracle Retail Financial Integration | =19.0.1 | |
Oracle Retail Integration Bus | =14.1.3.2 | |
Oracle Retail Integration Bus | =15.0.3.1 | |
Oracle Retail Integration Bus | =16.0.3 | |
Oracle Retail Integration Bus | =19.0.1 | |
Oracle Retail Merchandising System | =16.0.3 | |
Oracle Retail Merchandising System | =19.0.1 | |
Oracle WebLogic Server | =12.2.1.3.0 | |
Oracle WebLogic Server | =12.2.1.4.0 | |
Oracle WebLogic Server | =14.1.1.0.0 | |
VMware Spring Framework | ||
All of | ||
Any of | ||
VMware Spring Framework | <5.2.20 | |
VMware Spring Framework | >=5.3.0<5.3.18 | |
Oracle JDK | >=9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.