A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade tomcat-admin-webappsUpgrade tomcat-docs-webappUpgrade tomcat-jsvcUpgrade tomcat-webappsUpgrade tomcat-javadocUpgrade tomcat-jsp-2.3-apiUpgrade tomcatUpgrade tomcat-el-3.0-apiUpgrade tomcat-servlet-4.0-apiUpgrade tomcat-libUpgrade tomcat-servlet-3.1-api | Sep 28, 2023 | Apr 1, 2022 |
| Debian | — | No solution exists | May 15, 2025 | Apr 1, 2022 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 34298772 for version 12.2.1.3.0.Apply the Patch Set Update (PSU) 34236279 for version 12.2.1.4.0.Apply the Patch Set Update (PSU) 34429365 for version 14.1.1.0.0. | Jul 25, 2022 | Apr 1, 2022 |
| Spring | — | Upgrade to non vulnerable version of spring | Apr 1, 2022 | Mar 31, 2022 |
| Ubuntu | — | Upgrade libspring-orm-javaUpgrade libspring-core-javaUpgrade libspring-aop-javaUpgrade libspring-web-portlet-javaUpgrade libspring-oxm-java (Ubuntu Pro)Upgrade libspring-context-support-java (Ubuntu Pro)Upgrade libspring-transaction-javaUpgrade libspring-instrument-javaUpgrade libspring-web-java (Ubuntu Pro)Upgrade libspring-web-portlet-java (Ubuntu Pro)Upgrade libspring-instrument-java (Ubuntu Pro)Upgrade libspring-beans-javaUpgrade libspring-transaction-java (Ubuntu Pro)Upgrade libspring-web-servlet-javaUpgrade libspring-messaging-javaUpgrade libspring-core-java (Ubuntu Pro)Upgrade libspring-context-java (Ubuntu Pro)Upgrade libspring-jdbc-javaUpgrade libspring-oxm-javaUpgrade libspring-web-servlet-java (Ubuntu Pro)Upgrade libspring-aop-java (Ubuntu Pro)Upgrade libspring-beans-java (Ubuntu Pro)Upgrade libspring-expression-java (Ubuntu Pro)Upgrade libspring-messaging-java (Ubuntu Pro)Upgrade libspring-jms-javaUpgrade libspring-jms-java (Ubuntu Pro)Upgrade libspring-expression-javaUpgrade libspring-web-javaUpgrade libspring-context-support-javaUpgrade libspring-jdbc-java (Ubuntu Pro) | Dec 19, 2024 | Apr 1, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub