cisco-sa-java-spring-rce-Zx9GUc67: Vulnerability in Spring Framework Affecting Cisco Products: March 2022

Published Apr 1, 2022
·
Updated

On March 31, 2022, the following critical vulnerability in the Spring Framework affecting Spring MVC and Spring WebFlux applications running on JDK 9+ was released: CVE-2022-22965: Spring Framework RCE via Data Binding on JDK 9+ For a description of this vulnerability, see VMware Spring Framework Security Vulnerability Report. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67

Other sources

On March 31, 2022, the following critical vulnerability in the Spring Framework affecting Spring MVC and Spring WebFlux applications running on JDK 9+ was released:     CVE-2022-22965: Spring Framework RCE via Data Binding on JDK 9+For a description of this

Credit

This vulnerability was publicly disclosed by VMware on March 31, 2022.

Affected Software

1 affected component
VMware Spring Framework

Event History

Apr 1, 2022
Advisory Published
11:45 PM
Data Sourced
11:45 PM
DescriptionSeverityWeakness
Data Sourced
via Cisco·11:45 PM
DescriptionSeverityWeaknessAffected Software

Child vulnerabilities

Contains the following vulnerabilities.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of cisco-sa-java-spring-rce-Zx9GUc67?

The severity of cisco-sa-java-spring-rce-Zx9GUc67 is critical due to the remote code execution vulnerability.

2

How do I fix cisco-sa-java-spring-rce-Zx9GUc67?

To fix cisco-sa-java-spring-rce-Zx9GUc67, upgrade to the latest version of the Spring Framework that addresses CVE-2022-22965.

3

What are the affected systems by cisco-sa-java-spring-rce-Zx9GUc67?

cisco-sa-java-spring-rce-Zx9GUc67 affects Spring MVC and Spring WebFlux applications running on JDK 9 and above.

4

What impact does cisco-sa-java-spring-rce-Zx9GUc67 have?

The impact of cisco-sa-java-spring-rce-Zx9GUc67 includes the potential for an attacker to execute arbitrary code on the server.

5

When was cisco-sa-java-spring-rce-Zx9GUc67 disclosed?

cisco-sa-java-spring-rce-Zx9GUc67 was disclosed on March 31, 2022.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203