Vulnerability record · CVE-2022-22963 · published 1 April 2022
CVE-2022-22963: Spring Cloud Function routing expression SpEL injection RCE
Vmware · Spring Cloud Function
Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions allow a user to supply a crafted SpEL expression as a routing-expression when routing functionality is enabled. The expression is evaluated server-side, leading to remote code execution and access to local resources. It is a critical, unauthenticated network-reachable flaw in a widely deployed Java framework.
Description
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable RCE with a CVSS of 9.8, KEV listing and near-maximum EPSS probability.
What it is
Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions allow a user to supply a crafted SpEL expression as a routing-expression when routing functionality is enabled. The expression is evaluated server-side, leading to remote code execution and access to local resources. It is a critical, unauthenticated network-reachable flaw in a widely deployed Java framework.
Impact
An attacker gains remote code execution in the context of the application, allowing arbitrary command execution and access to local resources on the host.
Attack surface
Reached over the network via the routing functionality by supplying a malicious routing-expression; the CVSS vector shows no privileges or user interaction required.
Exploitation
Listed in CISA KEV since 2022-08-25 with a required action deadline of 2022-09-15, and EPSS 30-day probability is 0.99938 (99.97th percentile); references include an Exploit-tagged Packet Storm entry. No ransomware campaign use is documented.
What to do
- Upgrade Spring Cloud Function to a fixed release per the VMware Tanzu advisory, and apply the Oracle CPU patches for affected Oracle products.
- Disable or restrict the routing functionality if it is not required, and avoid evaluating user-supplied routing expressions.
- Place affected services behind authentication and network controls so the routing endpoint is not exposed to untrusted clients.
- Monitor vendor advisories and redeploy dependent Oracle and VMware products that bundle the affected library.
Detection
- Inspect HTTP requests for routing-expression parameters or headers containing SpEL syntax such as T(, Runtime, or ProcessBuilder.
- Alert on outbound network connections or process creation spawned by Java application servers hosting Spring Cloud Function.
- Search application and WAF logs for anomalous expression strings or repeated requests to function routing endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-22963 to the Known Exploited Vulnerabilities catalog on 25 August 2022 as "VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 September 2022.
Affected products
28 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-22963 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-22963), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.