← לוח פגיעויות

CVE-2022-22947

קריטית 10.0 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
VMware Spring Cloud Gateway Code Injection Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.

מדדים

CVSS 3.1
10.0 (CRITICAL) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS — סבירות ניצול
98% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-94, CWE-917

מוצרים מושפעים

vmware: spring cloud gateway; oracle: commerce guided search; oracle: communications cloud native core binding support function; oracle: communications cloud native core console; oracle: communications cloud native core network exposure function; oracle: communications cloud native core network function cloud native environment; oracle: communications cloud native core network repository function; oracle: communications cloud native core network slice selection function; oracle: communications cloud native core security edge protection proxy; oracle: communications cloud native core service communication proxy

קישורים