LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2022-22947

CVE-2022-22947

VMware Spring Cloud Gateway Code Injection Vulnerability

CVSS 10 · CRITICAL ⚠ CISA KEV — ACTIVELY EXPLOITED
On the CISA KEV catalog

Confirmed exploited in the wild. Added 2022-05-16. Federal remediation due 2022-06-06.
Required action: Apply updates per vendor instructions.

Summary

In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.

CVSS 3.1 breakdown

Base score10 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack vectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeCHANGED
ConfidentialityHIGH
IntegrityHIGH
AvailabilityHIGH

Weakness type (CWE)

Affected products

Vmware spring cloud gatewayOracle commerce guided searchOracle communications cloud native core binding support functionOracle communications cloud native core consoleOracle communications cloud native core network exposure functionOracle communications cloud native core network function cloud native environmentOracle communications cloud native core network repository functionOracle communications cloud native core network slice selection functionOracle communications cloud native core security edge protection proxyOracle communications cloud native core service communication proxy
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD + CISA KEV. NVD last modified 2025-10-30. Always verify against the vendor advisory before acting.

Scroll to Top