S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-22965 Scanner

CVE-2022-22965 scanner - Remote Code Execution (RCE) vulnerability in Spring Framework

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.5k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2022-22965
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Spring Frameworkby n/a
Spring Framework versions 5.3.X prior to 5.3.18+, 5.2.x prior to 5.2.20+ and all old and unsupported versions
Updated Aug 22, 2026View on NVD →
Detail

The Spring Framework is a widely used Java-based application development framework. It provides developers with a comprehensive programming and configuration model for modern Java-based enterprise applications, including web, mobile, and cloud-native applications. The Spring Framework offers a variety of features, including inversion of control, security, data access, transaction management, and more. It is an excellent choice for developers who want to build robust and scalable applications in Java.

However, the Spring Framework has recently been found to be vulnerable to a critical remote code execution (RCE) exploit, tracked as CVE-2022-22965. This vulnerability affects the Spring MVC and Spring WebFlux applications running on JDK 9+. The attack is accomplished via data binding, and the application must be deployed as a WAR on Tomcat to be vulnerable. If the application is deployed as a Spring Boot executable jar, it is not vulnerable to the exploit. Nevertheless, the vulnerability's scope is extensive, and other attack vectors may be possible.

When exploited, CVE-2022-22965 can lead to a complete compromise of the vulnerable application's security. An attacker can execute arbitrary code on the targeted system, potentially leading to the theft of sensitive data, system takeovers, or other forms of malicious activity. Remote code execution vulnerabilities are severe and require prompt attention and mitigation to prevent exploitation.

Thanks to the pro features of the s4e.io platform, you can easily and quickly learn about vulnerabilities in your digital assets. This platform offers comprehensive vulnerability management that enables you to identify, assess, and prioritize vulnerabilities in your equipment. Moreover, you can monitor potential threats and quickly detect and respond to any attack. With s4e.io, you can rest assured that your digital assets are in good hands.

 

REFERENCES

Solution Advice

Fortunately, there are steps you can take to protect your applications against this vulnerability. Here are some best practices to follow:

  • Update your Spring Framework and its dependencies regularly
  • Configure your application to use Spring Boot executable jar instead of deploying WAR to Tomcat
  • Ensure that your servers and systems are adequately secured
  • Monitor your systems for any suspicious activity or anomalies
  • Enforce strict security policies for developers and system administrators.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.