CVE detail
CVE-2022-22965
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 16.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
34 source links · newest first
Black Basta, one of the most successful ransomware groups over the past several years, had a major leak of its internal communications recently. The logs provide a glimpse into the playbook of a high-profile ransomware group and its preferred methods for gaining initial access to networks, as analysis from security researchers shows. “Key attack vectors […]
newswww.csoonline.comMar 3, 2025, 8:00 AMResearchers have discovered a new malware attack campaign that exploits misconfigurations in Apache Hadoop and Flink, two technologies for processing big data sets and data streams. The attackers behind the campaign exploit these issues without authentication to deploy rootkits on the underlying systems and then install a Monero cryptocurrency mining program. “This attack is particularly […]
newswww.csoonline.comJan 11, 2024, 4:58 PM- Healthcare organizations in the crosshairs of cyberattackersHelp Net Security
In an era where cyber threats continue to evolve, healthcare organizations are increasingly targeted by malicious actors employing multiple attack vectors, according to Trustwave. In its new research, Trustwave SpiderLabs has documented the attack flow utilized by threat groups, shedding light on their tactics, techniques, and procedures. From phishing emails to exploiting known vulnerabilities and compromising third-party vendors, these persistent threats pose significant risks to the healthcare industry. Healthcare industry bears heavier financial burden While … More →
newswww.helpnetsecurity.comJul 18, 2023, 3:30 AM A new report from Trustwave SpiderLabs has revealed that the number of CVEs published so far this year could be as much as 35% higher than in the same period in 2021. The findings come from the security firm’s 2022 Telemetry Report. While organizations appear to be exhibiting greater awareness of effective patch management compared […]
newswww.csoonline.comAug 25, 2022, 2:06 PMRecent exploits observed in the wild are highlighted based on the availability of proofs of concept, the severity of the vulnerabilities the exploits are based on and the ease of exploitation.
vendorunit42.paloaltonetworks.comAug 19, 2022, 11:00 PMA threat actor, tracked as TAC-040, exploited Atlassian Confluence flaw CVE-2022-26134 to deploy previously undetected Ljl Backdoor. Cybersecurity firm Deepwatch reported that a threat actor, tracked as TAC-040, has likely exploited the CVE-2022-26134 flaw in Atlassian Confluence servers to deploy a previously undetected backdoor dubbed Ljl Backdoor. The attackers exploited the flaw in an attack […]
newssecurityaffairs.comAug 5, 2022, 8:49 AMThe 2022 Unit 42 Network Threat Trends Research Report includes an analysis of the CVEs most commonly exploited in 2021 and predictions for which CVEs attackers will likely focus on in the year to come.
vendorunit42.paloaltonetworks.comJul 21, 2022, 1:00 PMOracle on Tuesday announced that a total of 349 new security patches have been released as part of its July 2022 Critical Patch Update (CPU), including 230 for vulnerabilities that can be exploited by remote, unauthenticated attackers.
newswww.securityweek.comJul 20, 2022, 11:54 AM- 16th May – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 16th May, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research revealed a yearlong campaign targeting German companies, focused on German car dealerships and manufacturers. Threat actors used a vast infrastructure designed to mimic existing German companies and leveraged phishing […]
vendorresearch.checkpoint.comMay 16, 2022, 2:51 PM As part of its May 2022 Security Patch Day, SAP announced on Tuesday the release of eight new and four updated security notes, including three that address the recent Spring4Shell vulnerability in more products.
newswww.securityweek.comMay 11, 2022, 11:17 AMOracle on Tuesday announced the release of 520 security fixes as part of its April 2022 Critical Patch Update (CPU), including nearly 300 for vulnerabilities that can be exploited remotely without authentication.
newswww.securityweek.comApr 20, 2022, 9:57 AM- Spring4Shell: Assessing the riskCSO Online
When a significant vulnerability like Spring4Shell is discovered, how do you determine if you are at risk? Insurance or verification services might require you to run external tests on web properties. These reports often show spurious exposures that may or may not lead to more issues on your website. You must research false-positive reports and […]
newswww.csoonline.comApr 20, 2022, 9:00 AM A critical zero-day vulnerability known as Spring4Shell (CVE-2022-22965) has been discovered in Java Spring Core, a widely used open-source development kit present in numerous Java applications including the Apache Tomcat framework. The vulnerability allows for remote code execution that can enable an attacker to gain full network access. Scanning activity for Spring4Shell has been observed […]
newswww.csoonline.comApr 14, 2022, 10:54 PMCisco announced on Wednesday that updates released for its Wireless LAN Controller (WLC) software address a critical vulnerability that could allow an attacker to bypass authentication.
newswww.securityweek.comApr 14, 2022, 11:41 AMGerman software maker SAP announced on Tuesday that more than 30 new and updated security notes were released on its April 2022 Security Patch Day, including notes that deal with the Spring4Shell vulnerability.
newswww.securityweek.comApr 13, 2022, 10:11 AM- 11th April – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 11th April, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research discovered six applications spreading banking malware on Google Play Store by masquerading as anti-virus solutions, with over 15,000 downloads. The malware, known as ‘Sharkbot’, steals credentials and banking information […]
vendorresearch.checkpoint.comApr 11, 2022, 2:24 PM - Week in review: Disrupted Cyclops Blink botnet, public software apps at risk, Patch Tuesday forecastHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles and interviews: April 2022 Patch Tuesday forecast: Spring is in the air (and vulnerable) March Patch Tuesday releases followed in the footsteps of February with low numbers of CVEs reported and resolved, and all updates rated as important except one critical update for Microsoft Exchange Server. Log4Shell exploitation: Which applications may be targeted next? Spring4Shell (CVE-2022-22965) has dominated the information security news these … More →
newswww.helpnetsecurity.comApr 10, 2022, 8:00 AM Experts warn of a Mirai-based botnet exploiting the recently discovered Spring4Shell vulnerability in attacks in the wild. Trend Micro Threat Research reported that the recently discovered Spring4Shell vulnerability (CVE-2022-22965) is actively exploited by a Mirai-based botnet. Researchers from Chinese cybersecurity firm Qihoo 360 first reported the exploitation of the Spring4Shell by a Mirai-based botnet in early April. […]
newssecurityaffairs.comApr 9, 2022, 7:45 AMCybersecurity firm Trend Micro on Friday confirmed some earlier reports that the new Spring4Shell vulnerability has been exploited by the Mirai botnet. Two critical vulnerabilities have been patched recently in the popular Java application development framework Spring: CVE-2022-22965 (aka Spring4Shell and SpringShell) and CVE-2022-22963.
newswww.securityweek.comApr 8, 2022, 12:51 PMMarch Patch Tuesday releases followed in the footsteps of February with low numbers of CVEs reported and resolved, and all updates rated as important except one critical update for Microsoft Exchange Server. Could April Patch Tuesday provide the deluge of critical updates we were expecting last month? Security enhancements for Windows 11 Microsoft has clearly been busy working on security improvements in multiple arenas. Earlier this week, they announced an extensive set of security enhancements … More →
newswww.helpnetsecurity.comApr 8, 2022, 6:14 AMBusinesses have been at work since last week investigating whether their applications or third-party software products are vulnerable to Spring4Shell, a critical remote code execution (RCE) vulnerability impacting Spring Framework, one of the most popular development frameworks for Java applications. While exploitation attempts have already been observed in the wild, the rate at which developers […]
newswww.csoonline.comApr 5, 2022, 8:43 PMUS Government Agencies Instructed to Patch Spring4Shell Vulnerability Enterprise defenders have been provided information and tools to help them deal with Spring4Shell and potential attacks exploiting the vulnerability.
newswww.securityweek.comApr 5, 2022, 12:47 PM- CISA adds Spring4Shell to list of exploited vulnerabilitiesHelp Net Security
It’s been almost a week since the Spring4Shell vulnerability (CVE-2022-22965) came to light and since the Spring development team fixed it in new versions of the Spring Framework. There have been reports of scanning, exploit attempts and attempts to deploy a web shell on vulnerable systems, but it seems that a successful exploitation has yet to be documented. The consensus amongst the thread and everybody I talk to in private is there are no incidents … More →
newswww.helpnetsecurity.comApr 5, 2022, 11:07 AM The U.S. CISA added the recently disclosed remote code execution (RCE) vulnerability Spring4Shell to its Known Exploited Vulnerabilities Catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the recently disclosed CVE-2022-22965 (aka Spring4Shell, CVSS score: 9.8) flaw in the Spring Framework, along with three other issues, to its Known Exploited Vulnerabilities Catalog. According to Binding Operational Directive (BOD) […]
newssecurityaffairs.comApr 5, 2022, 11:02 AM- Log4Shell exploitation: Which applications may be targeted next?Help Net Security
Spring4Shell (CVE-2022-22965) has dominated the information security news these last six days, but Log4Shell (CVE-2021-44228) continues to demand attention and action from enterprise defenders as diverse vulnerable applications are being targeted in attacks in the wild. Attackers in the wild exploiting Log4Shell Log4Shell is widespread because Apache Log4j – the logging library that it affects – is widely used. While its exploitability depends on the Java version, the Log4j version (only Log4j v2 is vulnerable) … More →
newswww.helpnetsecurity.comApr 5, 2022, 9:07 AM WhiteSource launched WhiteSource Spring4Shell Detect, a free command-line interface (CLI) tool that quickly scans projects to find vulnerable open source libraries for CVE-2022-22965, also known as Spring4Shell. Spring4Shell is a remote code execution (RCE) vulnerability in Spring, one of the most popular open-source frameworks for Java applications in use today. While we are still learning about this vulnerability, its impact is likely on par with that of Log4j and it is considered extremely critical with … More →
newswww.helpnetsecurity.comApr 5, 2022, 2:10 AMVMware released security updates to address the critical remote code execution vulnerability known as Spring4Shell. VMware has published security updates to address the critical remote code execution vulnerability known as Spring4Shell (CVE-2022-22965). According to the virtualization giant, the flaw impacts many of its cloud computing and virtualization products. The Spring4Shell issue was disclosed last week, […]
newssecurityaffairs.comApr 4, 2022, 8:06 PM- 4th April – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 4th April, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research (CPR) revealed a large spike in attacks committed by advanced persistent threat groups (APTs) around the world, using lures utilizing the war between Russia and Ukraine. Most of the […]
vendorresearch.checkpoint.comApr 4, 2022, 3:03 PM Companies are assessing the impact of the Spring vulnerability dubbed Spring4Shell on their products, and while some vendors have started releasing patches, many have determined that their products do not appear to be affected.
newswww.securityweek.comApr 4, 2022, 10:41 AMThe Spring zero-day vulnerability named Spring4Shell (SpringShell) has been patched, just as several cybersecurity firms have confirmed seeing exploitation attempts.
newswww.securityweek.comApr 1, 2022, 10:11 AM- Spring4Shell: New info and fixes (CVE-2022-22965)Help Net Security
In this video for Help Net Security, Ax Sharma, Senior Security Researcher at Sonatype, talks about the latest developments regarding Spring4Shell, the unauthenticated RCE zero-day vulnerability in Spring Core whose existence has finally been confirmed by its developers. Spring4Shell has been catalogued as CVE-2022-22965 and fixed in Spring Framework 5.3.18 and 5.2.20, and Spring Boot (which depends on the Spring Framework) 2.5.12 and 2.6.6. “The vulnerability impacts Spring MVC and Spring WebFlux applications running on … More →
newswww.helpnetsecurity.comApr 1, 2022, 6:20 AM CVE-2022-22965, aka SpringShell, is a remote code execution vulnerability in the Spring Framework. We provide a root cause analysis and mitigations.
vendorunit42.paloaltonetworks.comMar 31, 2022, 11:30 PMA remote code execution vulnerability in Spring Framework has sparked fears that it could have a widespread impact across enterprise environments. Spring is one of the most popular open-source frameworks for developing Java applications. The flaw, which has since been dubbed SpringShell or Spring4Shell, came to light when a Chinese developer released a proof-of-concept (PoC) […]
newswww.csoonline.comMar 31, 2022, 5:12 PM- Spring4Shell: No need to panic, but mitigations are advisedHelp Net Security
Security teams around the world got another shock on Thursday when news of disclosure of a PoC for an unauthenticated RCE zero-day vulnerability in Spring Core, a massively popular framework for building modern Java-based enterprise applications, began circulating online. Thanks to many security researchers, the situation is a bit clearer today and there’s no need to panic just yet: Unlike Log4Shell, this new flaw – with no official CVE and currently nicknamed Spring4Shell – seems … More →
newswww.helpnetsecurity.comMar 31, 2022, 10:38 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2022-22963CVSS 9.8 · Critical
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a…
- CVE-2020-36518CVSS 7.5 · High
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
- CVE-2022-22947CVSS 10.0 · Critical
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and uns…
- CVE-2021-22118CVSS 7.8 · High
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary…
- CVE-2020-14340CVSS 5.9 · Medium
A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attack…
- CVE-2021-39144CVSS 8.5 · High
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute comman…