CVE-2022-22963 in VMware and Oracle Products
Published on April 1, 2022
Known Exploited Vulnerability
This VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
The following remediation steps are recommended / required by September 15, 2022: Apply updates per vendor instructions.
Vulnerability Analysis
CVE-2022-22963 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. It has the highest possible exploitability rating (3.9). The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
What is an EL Injection Vulnerability?
The software constructs all or part of an expression language (EL) statement in a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.
CVE-2022-22963 has been classified to as an EL Injection vulnerability or weakness.
Products Associated with CVE-2022-22963
You can be notified by stack.watch whenever vulnerabilities like CVE-2022-22963 are published in these products:
What versions are vulnerable to CVE-2022-22963?
- VMware Spring Cloud Function Version 3.2.0 through 3.2.2
- VMware Spring Cloud Function Up to Version 3.1.6
- Oracle Sd Wan Edge Version 9.0
- Oracle Retail Xstore Point Of Service Version 20.0.1
- Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 1.7.0
- Oracle Banking Cash Management Version 14.5
- Oracle Banking Trade Finance Process Management Version 14.5
- Oracle Banking Credit Facilities Process Management Version 14.5
- Oracle Banking Corporate Lending Process Management Version 14.5
- Oracle Banking Supply Chain Finance Version 14.5
- Oracle Sd Wan Edge Version 9.1
- Oracle Banking Liquidity Management Version 14.5
- Oracle Banking Liquidity Management Version 14.2
- Oracle Banking Virtual Account Management Version 14.5
- Oracle Financial Services Enterprise Case Management Version 8.1.1.0
- Oracle Financial Services Enterprise Case Management Version 8.1.1.1
- Oracle Financial Services Behavior Detection Platform Version 8.1.2.0
- Oracle Financial Services Behavior Detection Platform Version 8.1.1.1
- Oracle Financial Services Behavior Detection Platform Version 8.1.1.0
- Oracle Mysql Enterprise Monitor Up to Version 8.0.29
- Oracle Communications Cloud Native Core Console Version 1.9.0
- Oracle Communications Cloud Native Core Policy Version 1.15.0
- Oracle Communications Communications Policy Management Version 12.6.0.0.0
- Oracle Communications Cloud Native Core Unified Data Repository Version 1.15.0
- Oracle Communications Cloud Native Core Unified Data Repository Version 22.1.0
- Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 22.1.0
- Oracle Communications Cloud Native Core Policy Version 22.1.0
- Oracle Communications Cloud Native Core Network Slice Selection Function Version 1.8.0
- Oracle Communications Cloud Native Core Network Slice Selection Function Version 22.1.0
- Oracle Communications Cloud Native Core Network Repository Function Version 1.15.0
- Oracle Communications Cloud Native Core Network Repository Function Version 22.1.0
- Oracle Communications Cloud Native Core Network Function Cloud Native Environment Version 22.1.0
- Oracle Communications Cloud Native Core Network Function Cloud Native Environment Version 1.10.0
- Oracle Communications Cloud Native Core Network Exposure Function Version 22.1.0
- Oracle Communications Cloud Native Core Console Version 22.1.0
- Oracle Communications Cloud Native Core Automated Test Suite Version 22.1.0
- Oracle Communications Cloud Native Core Automated Test Suite Version 1.9.0
- Oracle Product Lifecycle Analytics Version 3.6.1.0
- Oracle Retail Xstore Point Of Service Version 21.0.0
- Oracle Financial Services Enterprise Case Management Version 8.1.2.0
- Oracle Financial Services Analytical Applications Infrastructure Version 8.1.2.0
- Oracle Financial Services Analytical Applications Infrastructure Version 8.1.1.0
- Oracle Banking Origination Version 14.5
- Oracle Banking Electronic Data Exchange Corporates Version 14.5
- Oracle Banking Branch Version 14.5
- Oracle Communications Cloud Native Core Policy Version 22.1.3
- Oracle Communications Cloud Native Core Network Function Cloud Native Environment Version 22.1.2