← Vulnerability feed

Vulnerability record · CVE-2022-22965 · published 1 April 2022

CVE-2022-22965: Spring Framework data binding remote code execution (Spring4Shell)

Vmware · Spring Framework

Spring MVC and Spring WebFlux applications on JDK 9+ can be exploited through data binding to achieve remote code execution. The known exploit path requires a Tomcat WAR deployment, though the underlying flaw is more general and other exploitation methods may exist. This is a critical, unauthenticated network-reachable flaw in a widely deployed framework.

9.8 CVSS 3.1 Critical CISA KEV since 4 Apr 2022 EPSS 100% · top 0.1% CWE-94 · Code injection
9.8CVSS 3.1 base score, v2 7.5
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
38Affected product versions listed by NVD
18References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, CISA KEV listing, near-certain EPSS probability, and public exploit code make this an urgent, actively exploited RCE in a ubiquitous framework.

What it is

Spring MVC and Spring WebFlux applications on JDK 9+ can be exploited through data binding to achieve remote code execution. The known exploit path requires a Tomcat WAR deployment, though the underlying flaw is more general and other exploitation methods may exist. This is a critical, unauthenticated network-reachable flaw in a widely deployed framework.

Impact

An unauthenticated attacker can execute arbitrary code on the application server, leading to full host compromise, data theft, and lateral movement. Successful exploitation gives the attacker the privileges of the application process.

Attack surface

Reachable over the network via HTTP requests to a vulnerable Spring MVC or WebFlux endpoint; no authentication or user interaction is required per the CVSS vector. The documented exploit specifically targets applications deployed as WAR files on Tomcat with JDK 9 or later.

Exploitation

CVE-2022-22965 is listed in CISA KEV with a 2022-04-25 remediation due date, and EPSS shows a 30-day probability of 0.99638 (99.6th percentile). Public exploit code is referenced in Packet Storm advisories, confirming active exploitation in the wild.

What to do

  • Upgrade Spring Framework to a fixed release per the VMware Tanzu advisory and apply vendor patches for affected products (Oracle, Cisco, Siemens, Veritas).
  • If immediate patching is not possible, apply the vendor-recommended mitigation (e.g., DataBinder disallowed fields) or deploy as a Spring Boot executable jar rather than a Tomcat WAR.
  • Remove or restrict unnecessary Tomcat access log and other writable classpath directories that the exploit abuses.
  • Inventory all Spring MVC/WebFlux applications on JDK 9+ and prioritize internet-facing and WAR-deployed instances.
  • Monitor vendor advisories for updated guidance, as the flaw is more general than the initial Tomcat WAR exploit path.

Detection

  • Hunt for HTTP requests containing class.module.classLoader patterns or other suspicious data-binding parameter names in web access logs.
  • Monitor for unexpected creation or modification of JSP files, especially under Tomcat access log or webapp directories.
  • Alert on outbound network connections or child processes spawned by the Java application server that are not part of normal behavior.
  • Use file integrity monitoring on web application directories and classpath locations to detect dropped webshells.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-22965 to the Known Exploited Vulnerabilities catalog on 4 April 2022 as "Spring Framework JDK 9+ Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 25 April 2022.

Affected products

38 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/167011/Spring4Shell-Spring-Framework-Class-Property-Remote-Code-Execution.html Third Party AdvisoryVDB Entry
https://cert-portal.siemens.com/productcert/pdf/ssa-254054.pdf PatchThird Party Advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005 Third Party Advisory
https://tanzu.vmware.com/security/cve-2022-22965 MitigationVendor Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67 Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html PatchThird Party Advisory
http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/167011/Spring4Shell-Spring-Framework-Class-Property-Remote-Code-Execution.html Third Party AdvisoryVDB Entry
https://cert-portal.siemens.com/productcert/pdf/ssa-254054.pdf PatchThird Party Advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005 Third Party Advisory
https://tanzu.vmware.com/security/cve-2022-22965 MitigationVendor Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67 Third Party Advisory
https://www.kb.cert.org/vuls/id/970766 US Government Resource
https://www.oracle.com/security-alerts/cpuapr2022.html Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html PatchThird Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22965 US Government Resource

Track CVE-2022-22965 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2022-22947Spring Cloud Gateway Actuator endpoint code injectionSpring Cloud Gateway versions before 3.1.1+ and 3.0.7+ allow code injection when the Gateway Actuator endpoint is enabled, exposed and unsecured. A c…KEVEPSS 98%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2022-22963Spring Cloud Function routing expression SpEL injection RCESpring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions allow a user to supply a crafted SpEL expression as a routing-expression w…KEVEPSS 100%analysed9.8CVE-2020-2555Oracle Coherence T3 deserialization allows unauthenticated remote code executionOracle Coherence (Fusion Middleware) deserializes untrusted data reachable over the T3 protocol, allowing an unauthenticated network attacker to exec…KEVEPSS 97%analysed9.8CVE-2017-1000353Jenkins CLI Java deserialization allows unauthenticated remote code executionJenkins 2.56 and earlier, and 2.46.1 LTS and earlier, deserialize attacker-supplied Java SignedObject data sent to the Jenkins CLI, bypassing the exi…KEVEPSS 100%analysed8.5CVE-2021-39144XStream deserialization allows remote command executionXStream, a Java library that serializes objects to and from XML, can execute host commands when a remote attacker with sufficient rights manipulates …KEVEPSS 98%analysed9.8CVE-2026-70953Oracle commerce platform missing authentication for critical function vulnerabilityVulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is aff…EPSS 0.51%9.8CVE-2026-70954Oracle commerce platform missing authentication for critical function vulnerabilityVulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is aff…EPSS 0.51%

Source: NIST National Vulnerability Database (record CVE-2022-22965), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.