CVE-2022-22947
קריטית 10.0 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- VMware Spring Cloud Gateway Code Injection Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.
מדדים
- CVSS 3.1
-
10.0 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - EPSS — סבירות ניצול
- 98% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-94, CWE-917
מוצרים מושפעים
vmware: spring cloud gateway; oracle: commerce guided search; oracle: communications cloud native core binding support function; oracle: communications cloud native core console; oracle: communications cloud native core network exposure function; oracle: communications cloud native core network function cloud native environment; oracle: communications cloud native core network repository function; oracle: communications cloud native core network slice selection function; oracle: communications cloud native core security edge protection proxy; oracle: communications cloud native core service communication proxy
קישורים
- https://tanzu.vmware.com/security/cve-2022-22947 MitigationVendor Advisory
- https://tanzu.vmware.com/security/cve-2022-22947 MitigationVendor Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html PatchThird Party Advisory
- http://packetstormsecurity.com/files/166219/Spring-Cloud-Gateway-3.1.0-Remote-… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/168742/Spring-Cloud-Gateway-3.1.0-Remote-… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/166219/Spring-Cloud-Gateway-3.1.0-Remote-… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/168742/Spring-Cloud-Gateway-3.1.0-Remote-… ExploitThird Party AdvisoryVDB Entry