← לוח פגיעויות

CVE-2022-22963

קריטית 9.8 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

מדדים

CVSS 3.1
9.8 (CRITICAL) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
100% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-94, CWE-917

מוצרים מושפעים

vmware: spring cloud function; oracle: banking branch; oracle: banking cash management; oracle: banking corporate lending process management; oracle: banking credit facilities process management; oracle: banking electronic data exchange for corporates; oracle: banking liquidity management; oracle: banking origination; oracle: banking supply chain finance; oracle: banking trade finance process management; oracle: banking virtual account management; oracle: communications cloud native core automated test suite; oracle: communications cloud native core console; oracle: communications cloud native core network exposure function; oracle: communications cloud native core network function cloud native environment

קישורים