CVE-2022-22947: VMware Spring Cloud Gateway Code Injection Vulnerability
Critical severity, CVSS 10.0. Actively exploited: in CISA KEV since 2022-05-16. EPSS: 98.3% chance of exploitation in the next 30 days.
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.
Affected products
- Oracle Commerce Guided Search: version 11.3.2 only
- Oracle Communications Cloud Native Core Binding Support Function: version 1.11.0 only; version 22.1.3 only
- Oracle Communications Cloud Native Core Console: version 22.2.0 only
- Oracle Communications Cloud Native Core Network Exposure Function: version 22.1.0 only
- Oracle Communications Cloud Native Core Network Function Cloud Native Environment: version 1.10.0 only
- Oracle Communications Cloud Native Core Network Repository Function: version 1.15.0 only; version 1.15.1 only; version 22.1.2 only; version 22.2.0 only
- Oracle Communications Cloud Native Core Network Slice Selection Function: version 1.8.0 only; version 22.1.0 only
- Oracle Communications Cloud Native Core Security Edge Protection Proxy: version 22.1.1 only
- Oracle Communications Cloud Native Core Service Communication Proxy: version 1.15.0 only
- VMware Spring Cloud Gateway: before 3.0.7 (fixed in 3.0.7); version 3.1.0 only
Published 2022-03-03. Last modified 2026-06-17.