cisco-sa-java-spring-rce-Zx9GUc67: Vulnerability in Spring Framework Affecting Cisco Products: March 2022
On March 31, 2022, the following critical vulnerability in the Spring Framework affecting Spring MVC and Spring WebFlux applications running on JDK 9+ was released: CVE-2022-22965: Spring Framework RCE via Data Binding on JDK 9+ For a description of this vulnerability, see VMware Spring Framework Security Vulnerability Report. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67
Other sources
On March 31, 2022, the following critical vulnerability in the Spring Framework affecting Spring MVC and Spring WebFlux applications running on JDK 9+ was released: CVE-2022-22965: Spring Framework RCE via Data Binding on JDK 9+For a description of this
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-java-spring-rce-Zx9GUc67?
The severity of cisco-sa-java-spring-rce-Zx9GUc67 is critical due to the remote code execution vulnerability.
How do I fix cisco-sa-java-spring-rce-Zx9GUc67?
To fix cisco-sa-java-spring-rce-Zx9GUc67, upgrade to the latest version of the Spring Framework that addresses CVE-2022-22965.
What are the affected systems by cisco-sa-java-spring-rce-Zx9GUc67?
cisco-sa-java-spring-rce-Zx9GUc67 affects Spring MVC and Spring WebFlux applications running on JDK 9 and above.
What impact does cisco-sa-java-spring-rce-Zx9GUc67 have?
The impact of cisco-sa-java-spring-rce-Zx9GUc67 includes the potential for an attacker to execute arbitrary code on the server.
When was cisco-sa-java-spring-rce-Zx9GUc67 disclosed?
cisco-sa-java-spring-rce-Zx9GUc67 was disclosed on March 31, 2022.