CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
100.0%
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
Vendor | Product | Version | CPE |
---|---|---|---|
vmware | spring_cloud_function | * | cpe:2.3:a:vmware:spring_cloud_function:*:*:*:*:*:*:*:* |
oracle | banking_branch | 14.5 | cpe:2.3:a:oracle:banking_branch:14.5:*:*:*:*:*:*:* |
oracle | banking_cash_management | 14.5 | cpe:2.3:a:oracle:banking_cash_management:14.5:*:*:*:*:*:*:* |
oracle | banking_corporate_lending_process_management | 14.5 | cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.5:*:*:*:*:*:*:* |
oracle | banking_credit_facilities_process_management | 14.5 | cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.5:*:*:*:*:*:*:* |
oracle | banking_electronic_data_exchange_for_corporates | 14.5 | cpe:2.3:a:oracle:banking_electronic_data_exchange_for_corporates:14.5:*:*:*:*:*:*:* |
oracle | banking_liquidity_management | 14.2 | cpe:2.3:a:oracle:banking_liquidity_management:14.2:*:*:*:*:*:*:* |
oracle | banking_liquidity_management | 14.5 | cpe:2.3:a:oracle:banking_liquidity_management:14.5:*:*:*:*:*:*:* |
oracle | banking_origination | 14.5 | cpe:2.3:a:oracle:banking_origination:14.5:*:*:*:*:*:*:* |
oracle | banking_supply_chain_finance | 14.5 | cpe:2.3:a:oracle:banking_supply_chain_finance:14.5:*:*:*:*:*:*:* |
packetstormsecurity.com/files/173430/Spring-Cloud-3.2.2-Remote-Command-Execution.html
psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005
tanzu.vmware.com/security/cve-2022-22963
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-scf-rce-DQrHhJxH
www.oracle.com/security-alerts/cpuapr2022.html
www.oracle.com/security-alerts/cpujul2022.html
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
100.0%