← Vulnerability feed

Vulnerability record · CVE-2010-1622 · published 21 June 2010

CVE-2010-1622: Spring Framework class loader manipulation enables remote code execution

Oracle · Fusion Middleware

SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file. The flaw is a code injection issue in how the framework binds request parameters to object properties, letting an attacker overwrite the class loader's URL list. It matters because it turns a simple HTTP request into remote code execution on the application server.

6.0 CVSS 2.0 Medium EPSS 52% · top 1.1% CWE-94 · Code injection
6.0CVSS 2.0 base score
52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
28References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file.

AV:N/AC:M/Au:S/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityPublic exploit code and very high EPSS probability make exploitation likely, though the CVSS 2.0 score is only 6.0 (MEDIUM) and authentication is required.

What it is

SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file. The flaw is a code injection issue in how the framework binds request parameters to object properties, letting an attacker overwrite the class loader's URL list. It matters because it turns a simple HTTP request into remote code execution on the application server.

Impact

An attacker can load and execute a malicious JAR, gaining arbitrary code execution in the context of the Spring application. This can lead to full compromise of the application and its host.

Attack surface

Reached over the network through HTTP requests to a Spring application that binds request parameters to objects. The CVSS vector AV:N/AC:M/Au:S indicates network access with medium complexity and single authentication required; no user interaction is described.

Exploitation

Public exploit code exists (Exploit-DB 13918 and SecurityFocus references tagged Exploit), and EPSS is 0.51849 (98.9th percentile), indicating high likelihood of exploitation. It is not listed in CISA KEV.

What to do

  • Upgrade Spring Framework to 2.5.6.SEC02, 2.5.7.SR01, 3.0.3 or later.
  • Apply vendor patches for Oracle Fusion Middleware and Apache Geronimo components that bundle the affected Spring Framework.
  • Restrict or disable data binding of request parameters to class loader properties, and validate/whitelist bindable fields.
  • Run the application with least privilege and isolate it to limit the impact of code execution.

Detection

  • Search HTTP request logs for parameters containing class.classLoader or classLoader.URLs.
  • Monitor for requests referencing jar: URLs in parameter values.
  • Alert on unexpected JAR loading or outbound connections to attacker-controlled hosts from the application server.
  • Review application server logs for class loader manipulation errors or unusual class loading activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://geronimo.apache.org/2010/07/21/apache-geronimo-v216-released.html Vendor Advisory
http://geronimo.apache.org/21x-security-report.html Vendor Advisory
http://geronimo.apache.org/22x-security-report.html Vendor Advisory
http://secunia.com/advisories/41016
http://secunia.com/advisories/41025
http://secunia.com/advisories/43087
http://www.exploit-db.com/exploits/13918 Exploit
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
http://www.redhat.com/support/errata/RHSA-2011-0175.html
http://www.securityfocus.com/archive/1/511877 Exploit
http://www.securityfocus.com/bid/40954
http://www.securitytracker.com/id/1033898
http://www.springsource.com/security/cve-2010-1622 ExploitVendor Advisory
http://www.vupen.com/english/advisories/2011/0237
http://geronimo.apache.org/2010/07/21/apache-geronimo-v216-released.html Vendor Advisory
http://geronimo.apache.org/21x-security-report.html Vendor Advisory
http://geronimo.apache.org/22x-security-report.html Vendor Advisory
http://secunia.com/advisories/41016
http://secunia.com/advisories/41025
http://secunia.com/advisories/43087
http://www.exploit-db.com/exploits/13918 Exploit
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
http://www.redhat.com/support/errata/RHSA-2011-0175.html
http://www.securityfocus.com/archive/1/511877 Exploit
http://www.securityfocus.com/bid/40954
http://www.securitytracker.com/id/1033898
http://www.springsource.com/security/cve-2010-1622 ExploitVendor Advisory
http://www.vupen.com/english/advisories/2011/0237

Track CVE-2010-1622 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2012-1710Oracle Fusion Middleware WebCenter Forms Recognition unspecified flawCVE-2012-1710 is an unspecified vulnerability in the Oracle WebCenter Forms Recognition component of Oracle Fusion Middleware 10.1.3.5, reachable thr…KEVEPSS 7.8%analysed9.1CVE-2012-3152Oracle Fusion Middleware Reports Developer arbitrary file read and uploadOracle Fusion Middleware's Reports Developer component (Report Server) contains an unspecified flaw that lets remote attackers affect confidentiality…KEVEPSS 99%analysed4.7CVE-2012-0518Oracle Fusion Middleware SSO open redirect flawOracle Fusion Middleware 10.1.4.3.0 contains an unspecified open redirect vulnerability in the Application Server Single Sign-On component, tracked a…KEVEPSS 4.7%analysed10.0CVE-2013-2380Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware R27.7.4 and earlier and R28.2.6 and earlier allows remote attac…EPSS 2.1%10.0CVE-2012-3135Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware 28.2.3 and before, and 27.7.2 and earlier, allows remote attack…EPSS 3.8%10.0CVE-2010-3510Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.0, 9.1, 9.2.3, 10.0.2, 10.3.2, and 10.3.3 allows remo…EPSS 2.7%9.8CVE-2020-10683Dom4j project dom4j xml external entity (xxe) vulnerabilitydom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is po…EPSS 7.3%9.4CVE-2010-3599Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affec…EPSS 16%

Source: NIST National Vulnerability Database (record CVE-2010-1622), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.