Lucene search

K
vmwareVMwareVMSA-2022-0010.1
HistoryApr 02, 2022 - 12:00 a.m.

VMware Response to Spring Framework Remote Code Execution Vulnerability (CVE-2022-22965)

2022-04-0200:00:00
www.vmware.com
112

0.975 High

EPSS

Percentile

100.0%

1. Impacted Products
  • VMware Tanzu Application Service for VMs

  • VMware Tanzu Operations Manager

  • VMware Tanzu Kubernetes Grid Integrated Edition (TKGI)

2. Introduction

A critical vulnerability in Spring Framework project identified by CVE-2022-22965 has been publicly disclosed which impacts VMware products.

3. Problem Description

Description

Multiple products impacted by remote code execution vulnerability (CVE-2022-22965).

Known Attack Vectors

A malicious actor with network access to an impacted VMware product may exploit this issue to gain full control of the target system.

Resolution

Fixes for CVE-2022-22965 are documented in the ‘Fixed Version’ column of the ‘Response Matrix’ below.

Workarounds

Workarounds for CVE-2022-22965 are documented in the ‘Workarounds’ column of the ‘Response Matrix’ below.

Additional Documentation

None.

Notes

  • At the time of this publication, VMware has reviewed its product portfolio and found that the products listed in this advisory are affected. VMware continues to investigate this vulnerability, and will update the advisory should any changes evolve.
  • VMware is aware of reports that exploitation of CVE-2022-22965 has occurred in the wild.

Acknowledgements

None.