Vulnerability record · CVE-2010-1622 · published 21 June 2010
CVE-2010-1622: Spring Framework class loader manipulation enables remote code execution
Oracle · Fusion Middleware
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file. The flaw is a code injection issue in how the framework binds request parameters to object properties, letting an attacker overwrite the class loader's URL list. It matters because it turns a simple HTTP request into remote code execution on the application server.
Description
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file.
AV:N/AC:M/Au:S/C:P/I:P/A:P
Automated analysis
high priorityPublic exploit code and very high EPSS probability make exploitation likely, though the CVSS 2.0 score is only 6.0 (MEDIUM) and authentication is required.
What it is
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file. The flaw is a code injection issue in how the framework binds request parameters to object properties, letting an attacker overwrite the class loader's URL list. It matters because it turns a simple HTTP request into remote code execution on the application server.
Impact
An attacker can load and execute a malicious JAR, gaining arbitrary code execution in the context of the Spring application. This can lead to full compromise of the application and its host.
Attack surface
Reached over the network through HTTP requests to a Spring application that binds request parameters to objects. The CVSS vector AV:N/AC:M/Au:S indicates network access with medium complexity and single authentication required; no user interaction is described.
Exploitation
Public exploit code exists (Exploit-DB 13918 and SecurityFocus references tagged Exploit), and EPSS is 0.51849 (98.9th percentile), indicating high likelihood of exploitation. It is not listed in CISA KEV.
What to do
- Upgrade Spring Framework to 2.5.6.SEC02, 2.5.7.SR01, 3.0.3 or later.
- Apply vendor patches for Oracle Fusion Middleware and Apache Geronimo components that bundle the affected Spring Framework.
- Restrict or disable data binding of request parameters to class loader properties, and validate/whitelist bindable fields.
- Run the application with least privilege and isolate it to limit the impact of code execution.
Detection
- Search HTTP request logs for parameters containing class.classLoader or classLoader.URLs.
- Monitor for requests referencing jar: URLs in parameter values.
- Alert on unexpected JAR loading or outbound connections to attacker-controlled hosts from the application server.
- Review application server logs for class loader manipulation errors or unusual class loading activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-1622 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-1622), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.