CWE
120
Advisory Published
Updated

cisco-sa-java-spring-rce-Zx9GUc67: Vulnerability in Spring Framework Affecting Cisco Products: March 2022

First published: Fri Apr 01 2022(Updated: )

On March 31, 2022, the following critical vulnerability in the Spring Framework affecting Spring MVC and Spring WebFlux applications running on JDK 9+ was released: CVE-2022-22965: Spring Framework RCE via Data Binding on JDK 9+ For a description of this vulnerability, see VMware Spring Framework Security Vulnerability Report. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67

Credit: This vulnerability was publicly disclosed by VMware on March 31 2022.

Affected SoftwareAffected VersionHow to fix
Spring Framework

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Child vulnerabilities

(Contains the following vulnerabilities)

Frequently Asked Questions

  • What is the severity of cisco-sa-java-spring-rce-Zx9GUc67?

    The severity of cisco-sa-java-spring-rce-Zx9GUc67 is critical due to the remote code execution vulnerability.

  • How do I fix cisco-sa-java-spring-rce-Zx9GUc67?

    To fix cisco-sa-java-spring-rce-Zx9GUc67, upgrade to the latest version of the Spring Framework that addresses CVE-2022-22965.

  • What are the affected systems by cisco-sa-java-spring-rce-Zx9GUc67?

    cisco-sa-java-spring-rce-Zx9GUc67 affects Spring MVC and Spring WebFlux applications running on JDK 9 and above.

  • What impact does cisco-sa-java-spring-rce-Zx9GUc67 have?

    The impact of cisco-sa-java-spring-rce-Zx9GUc67 includes the potential for an attacker to execute arbitrary code on the server.

  • When was cisco-sa-java-spring-rce-Zx9GUc67 disclosed?

    cisco-sa-java-spring-rce-Zx9GUc67 was disclosed on March 31, 2022.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203