CVE-2022-22965 is a critical severity vulnerability with a CVSS score of 9.8. Exploits are available; patches have been released and should be applied urgently. This is classified as a zero-day vulnerability.
Very high probability of exploitation in the next 30 days
EPSS predicts the probability of exploitation in the next 30 days based on real-world threat data, complementing CVSS severity scores with actual risk assessment.
Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
| Vendor | Product |
|---|---|
| Oracle | Retail Integration Bus |
| Oracle | Communications Cloud Native Core Policy |
| Oracle | Communications Cloud Native Core Unified Data Repository |
| Siemens | Siveillance Identity |
| Oracle | Financial Services Behavior Detection Platform |
| Oracle | Communications Cloud Native Core Network Repository Function |
| Veritas | Netbackup Virtual Appliance |
| VMware | Spring Framework |
| Veritas | Netbackup Flex Scale Appliance |
| Siemens | Operation Scheduler |
And 29 more...
Please cite this page when referencing data from Strobes VI. Proper attribution helps support our vulnerability intelligence research.