Vulnerability Details CVE-2022-22963
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.945
EPSS Ranking 100.0%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Proposed Action
When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
Ransomware Campaign
Unknown
Products affected by CVE-2022-22963
-
cpe:2.3:a:oracle:banking_branch:14.5
-
cpe:2.3:a:oracle:banking_cash_management:14.5
-
cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.5
-
cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.5
-
cpe:2.3:a:oracle:banking_electronic_data_exchange_for_corporates:14.5
-
cpe:2.3:a:oracle:banking_liquidity_management:14.2
-
cpe:2.3:a:oracle:banking_liquidity_management:14.5
-
cpe:2.3:a:oracle:banking_origination:14.5
-
cpe:2.3:a:oracle:banking_supply_chain_finance:14.5
-
cpe:2.3:a:oracle:banking_trade_finance_process_management:14.5
-
cpe:2.3:a:oracle:banking_virtual_account_management:14.5
-
cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.9.0
-
cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:22.1.0
-
cpe:2.3:a:oracle:communications_cloud_native_core_console:1.9.0
-
cpe:2.3:a:oracle:communications_cloud_native_core_console:22.1.0
-
cpe:2.3:a:oracle:communications_cloud_native_core_network_exposure_function:22.1.0
-
cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:1.10.0
-
cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:22.1.0
-
cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:22.1.2
-
cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.15.0
-
cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:22.1.0
-
cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.8.0
-
cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:22.1.0
-
cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.15.0
-
cpe:2.3:a:oracle:communications_cloud_native_core_policy:22.1.0
-
cpe:2.3:a:oracle:communications_cloud_native_core_policy:22.1.3
-
cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:1.7.0
-
cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:22.1.0
-
cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:1.15.0
-
cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:22.1.0
-
cpe:2.3:a:oracle:communications_communications_policy_management:12.6.0.0.0
-
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.1.0
-
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.2.0
-
cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.1.0
-
cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.1.1
-
cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.2.0
-
cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.1.0
-
cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.1.1
-
cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.2.0
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:-
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:2.3.14
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.0.25
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.0.4
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.1.0
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.1.1
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.1.2
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.1.3
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.1.3.7856
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.1.4
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.1.5
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.1.6
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.1.6.8003
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.1.7
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.0
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.1
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.10
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.1182
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.2
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.3
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.4
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.5
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.6
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.7
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.8
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.8.2223
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.9
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.0
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.1
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.2
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.2.1162
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.3
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.4
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.4.3247
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.5
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.6
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.6.3293
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.7
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.8
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.9
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.0
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.1
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.10
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.2
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.2.4181
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.3
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.4
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.4.4226
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.5
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.6
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.7
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.7.4297
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.8
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.9
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.9.4237
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.0
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.0.5135
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.1
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.11.5331
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.12
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.2
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.3
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.4
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.4.5235
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.5
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.6
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.6.5281
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.7
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.8
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.1
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.0
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.0.8131
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.1
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.14
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.18.1217
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.2
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.2.8191
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.20
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.21
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.22
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.23
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.25
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.29
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.3
-
cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1.0
-
cpe:2.3:a:oracle:retail_xstore_point_of_service:20.0.1
-
cpe:2.3:a:oracle:retail_xstore_point_of_service:21.0.0
-
cpe:2.3:a:oracle:sd-wan_edge:9.0
-
cpe:2.3:a:oracle:sd-wan_edge:9.1
-
cpe:2.3:a:vmware:spring_cloud_function:1.0.0
-
cpe:2.3:a:vmware:spring_cloud_function:1.0.1
-
cpe:2.3:a:vmware:spring_cloud_function:1.0.2
-
cpe:2.3:a:vmware:spring_cloud_function:2.0.0
-
cpe:2.3:a:vmware:spring_cloud_function:2.0.1
-
cpe:2.3:a:vmware:spring_cloud_function:2.0.2
-
cpe:2.3:a:vmware:spring_cloud_function:2.1.0
-
cpe:2.3:a:vmware:spring_cloud_function:2.1.1
-
cpe:2.3:a:vmware:spring_cloud_function:3.0.0
-
cpe:2.3:a:vmware:spring_cloud_function:3.0.1
-
cpe:2.3:a:vmware:spring_cloud_function:3.0.10
-
cpe:2.3:a:vmware:spring_cloud_function:3.0.11
-
cpe:2.3:a:vmware:spring_cloud_function:3.0.12
-
cpe:2.3:a:vmware:spring_cloud_function:3.0.13
-
cpe:2.3:a:vmware:spring_cloud_function:3.0.14
-
cpe:2.3:a:vmware:spring_cloud_function:3.0.2
-
cpe:2.3:a:vmware:spring_cloud_function:3.0.3
-
cpe:2.3:a:vmware:spring_cloud_function:3.0.4
-
cpe:2.3:a:vmware:spring_cloud_function:3.0.5
-
cpe:2.3:a:vmware:spring_cloud_function:3.0.6
-
cpe:2.3:a:vmware:spring_cloud_function:3.0.7
-
cpe:2.3:a:vmware:spring_cloud_function:3.0.8
-
cpe:2.3:a:vmware:spring_cloud_function:3.0.9
-
cpe:2.3:a:vmware:spring_cloud_function:3.1.0
-
cpe:2.3:a:vmware:spring_cloud_function:3.1.1
-
cpe:2.3:a:vmware:spring_cloud_function:3.1.2
-
cpe:2.3:a:vmware:spring_cloud_function:3.1.3
-
cpe:2.3:a:vmware:spring_cloud_function:3.1.4
-
cpe:2.3:a:vmware:spring_cloud_function:3.1.5
-
cpe:2.3:a:vmware:spring_cloud_function:3.1.6
-
cpe:2.3:a:vmware:spring_cloud_function:3.2.0
-
cpe:2.3:a:vmware:spring_cloud_function:3.2.1
-
cpe:2.3:a:vmware:spring_cloud_function:3.2.2