LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2022-22965

CVE-2022-22965

Spring Framework JDK 9+ Remote Code Execution Vulnerability

CVSS 9.8 · CRITICAL ⚠ CISA KEV — ACTIVELY EXPLOITED
On the CISA KEV catalog

Confirmed exploited in the wild. Added 2022-04-04. Federal remediation due 2022-04-25.
Required action: Apply updates per vendor instructions.

Summary

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

CVSS 3.1 breakdown

Base score9.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
IntegrityHIGH
AvailabilityHIGH

Weakness type (CWE)

Affected products

Vmware spring frameworkOracle jdkCisco cx cloud agentOracle communications cloud native core automated test suiteOracle communications cloud native core consoleOracle communications cloud native core network exposure functionOracle communications cloud native core network function cloud native environmentOracle communications cloud native core network repository functionOracle communications cloud native core network slice selection functionOracle communications cloud native core policyOracle communications cloud native core security edge protection proxyOracle communications cloud native core unified data repositoryOracle communications policy managementOracle financial services analytical applications infrastructureOracle financial services behavior detection platformOracle financial services enterprise case managementOracle mysql enterprise monitorOracle product lifecycle analyticsOracle retail xstore point of serviceOracle sd-wan edge
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD + CISA KEV. NVD last modified 2025-10-30. Always verify against the vendor advisory before acting.

Scroll to Top