A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade tomcat-docs-webappUpgrade tomcat-webappsUpgrade tomcat-el-3.0-apiUpgrade tomcat-servlet-4.0-apiUpgrade tomcat-jsp-2.3-apiUpgrade tomcatUpgrade tomcat-javadocUpgrade tomcat-admin-webappsUpgrade tomcat-jsvcUpgrade tomcat-servlet-3.1-apiUpgrade tomcat-lib | Sep 28, 2023 | Apr 1, 2022 |
| Debian | — | No solution exists | May 15, 2025 | Apr 1, 2022 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 34429365 for version 14.1.1.0.0.Apply the Patch Set Update (PSU) 34236279 for version 12.2.1.4.0.Apply the Patch Set Update (PSU) 34298772 for version 12.2.1.3.0. | Jul 25, 2022 | Apr 1, 2022 |
| Spring | — | Upgrade to non vulnerable version of spring | Apr 1, 2022 | Mar 31, 2022 |
| Ubuntu | — | Upgrade libspring-aop-java (Ubuntu Pro)Upgrade libspring-expression-javaUpgrade libspring-context-javaUpgrade libspring-jdbc-javaUpgrade libspring-context-support-javaUpgrade libspring-web-servlet-java (Ubuntu Pro)Upgrade libspring-orm-java (Ubuntu Pro)Upgrade libspring-web-javaUpgrade libspring-jdbc-java (Ubuntu Pro)Upgrade libspring-context-java (Ubuntu Pro)Upgrade libspring-messaging-java (Ubuntu Pro)Upgrade libspring-jms-java (Ubuntu Pro)Upgrade libspring-expression-java (Ubuntu Pro)Upgrade libspring-core-java (Ubuntu Pro)Upgrade libspring-oxm-javaUpgrade libspring-jms-javaUpgrade libspring-beans-java (Ubuntu Pro)Upgrade libspring-transaction-java (Ubuntu Pro)Upgrade libspring-transaction-javaUpgrade libspring-web-java (Ubuntu Pro)Upgrade libspring-oxm-java (Ubuntu Pro)Upgrade libspring-messaging-javaUpgrade libspring-web-portlet-java (Ubuntu Pro)Upgrade libspring-beans-javaUpgrade libspring-instrument-javaUpgrade libspring-orm-javaUpgrade libspring-context-support-java (Ubuntu Pro)Upgrade libspring-web-servlet-javaUpgrade libspring-web-portlet-javaUpgrade libspring-instrument-java (Ubuntu Pro)Upgrade libspring-core-javaUpgrade libspring-aop-java | Dec 19, 2024 | Apr 1, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub