• Language chooser
    • USA (English)
    • France (Français)

VMware Spring Cloud Function RCE Vulnerability

Released: Dec 20, 2022


High Severity

VMware Vendor

Vulnerability, Attack Type


Critical flaw found in Spring Cloud Function resulting in Remote Code Execution

In Spring Cloud Function versions 3.2.2, 3.1.6, and older versions, it is possible for an attacker to provide a specially crafted malicious expression that may result in remote code execution and access to local resources. With CVSS base score of 9.8 and publicly available proof of concept, this vulnerability should be seriously attended. Learn More »

Common Vulnerabilities and Exposures

CVE-2022-22963

Background

Spring Framework is an open source lightweight Java-based platform application development framework for creating high-performing, easily testable code. And, Spring Cloud provides developer tools to build distributed systems (e.g. configuration management, service discovery, etc). In March 2022, another critical vulnerability CVE-2022-22965 known as "Spring4Shell" also affected a flaw in the Spring Framework. See dedicated Outbreak Report for full details: https://www.fortiguard.com/outbreak-alert/spring4shell-vulnerability

Latest Development

Recent news and incidents related to cybersecurity threats encompassing various events such as data breaches, cyber-attacks, security incidents, and vulnerabilities discovered.


March 29, 2022: VMware published a vulnerability report: https://tanzu.vmware.com/security/cve-2022-22963


Dec 20, 2022: FortiGuard Labs is still seeing active attack attempts of the vulnerability CVE-2022-22963 and advises users to upgrade to recommended versions for mitigating the vulnerability.

The FortiGuard telemetry can be viewed at: https://www.fortiguard.com/encyclopedia/ips/51355

FortiGuard Cybersecurity Framework

Mitigate security threats and vulnerabilities by leveraging the range of FortiGuard Services.


PROTECT
  • IPS

  • Web App Security

  • Application Firewall

DETECT
  • Outbreak Detection

  • Threat Hunting

RESPOND
  • Automated Response

  • Assisted Response Services

RECOVER
  • InfoSec Services

IDENTIFY
  • Attack Surface Monitoring (Inside & Outside)

Threat Intelligence

Information gathered from analyzing ongoing cybersecurity events including threat actors, their tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), malware and related vulnerabilities.


Loading ...

Indicators of compromise Indicators of compromise
IOC Indicator List
Indicator Type Status
116.204.211.22 ip Active
194.145.227.21 ip Active
45.67.230.64 ip Active
https://45.67.230.64/wb.xml url Active
103.214.146.5 ip Active
45.155.204.146 ip Active
3de4e174c2c8612aebb3adef10027679 file Active
7e46801dd171bb5bf1771df1239d760c file Active
172.93.189.42 ip Active
100.26.40.121 ip Active
103.27.108.196 ip Active
112.5.154.7 ip Active
154.6.19.197 ip Active
37.120.203.76 ip Active
566b0187d8ff500d923859c98da2c96b8b581e93ac0c94d... file Active
00338c7ea14917bc085ae308d76a947defd1a7e3b3c1207... file Active
0d4ad08e561a3e285000a0c211063d58b543442d2208729... file Active
220179663c5a0974958caddf23709de8f26cdaee2c92c59... file Active
2c34b00ef26f5ca061177c31990726b91471c7e0efbeb5a... file Active
3d8291da28ab42ba18a58efc18fb62e1d114af631cab678... file Active
4b6b7b1a62cdeff56ce476b65447655af3f6c63e90e849e... file Active
5fb0c8f3daef02b9d2ab285d0bf348cf1cb7c36708b0034... file Active
74e6c938d4a2bc6d63c191588779fdb106fb215d9c57a16... file Active
83d3e7198f82ba06e87264a71b6dc9678a77738bfa90b32... file Active
8a4dedca3f21129c4759f065d0672433dc3ec9625c7c4e6... file Active
95e9e8e5e412813ff8e949946a5f8c1fbbfc3ead2e74233... file Active
9dc7ec24c42cbddb07f8a475297a52d64f8bcb9dc1a1090... file Active
af06644dd95a30d55162666331ea6de0832cdf6f3d1897b... file Active
afe718cc1ef596b4b7fc12060aca215b91ee6b48978cee6... file Active
http://45.95.169.143/The420smokeplace.dns/ url Active
45.12.2.252 ip Active
89.44.9.246 ip Active
http://45.95.169.143/The420smokeplace.dns url Active
00bc1ce81f79089670a7d2956df112ff29ee86d51ecad0d... file Active
01c758742f333d897b6d6fead725d91841f8a17bed6fb7f... file Active
07177233647e1ff382dde4803bc0651e5b052112a5450bd... file Active
0801d8f5c028457b5bad66917d39d17471659eb522c5813... file Active
12be4047b17c39993ea540b7bd857a665be2e205d455d06... file Active
12fd76f12e860d2931cc7e8b263933d9b82525f10116738... file Active
1416877edd6c4b18cbca4598b4c91b023113c51e9e8dbae... file Active
1adfc65c5ba75668d6f45e65ccb31100f9f8bf510435960... file Active
1c441e606233bbac68175731b0f35c0760a2da8e4002ef3... file Active
200c0d1c71d5c3faaba9ec5abcd1445b34c14fa66001557... file Active
208ffbdc18d19de0691d523fc3acddc1390223d8f5a5e62... file Active
23e718def31c7a37bcbfae15a4eb0725e106f7b73b238d9... file Active
27b5e1f1bbde28fbd2d6d31f64a1b96c32d064a23f5832c... file Active
2c91a412ecedf9e6998997d90467398e2a55373c0b9b339... file Active
2ec4d6fad356e771ecc18491d931c3cf510e10d3ff49d8a... file Active
2f08cab642d4da5ab2a1d9ed6e816b5dd20bff21b10b701... file Active
336008e2b7f2bf194a44984b36d0594d03103e363654027... file Active
3b1bbec6edbaf072ef57fa257279497e74ebf80ff038d21... file Active
3d73aea855fc012e2a49a4c98f293dc4836a284ddf74814... file Active
4485c594dce7c8444c2d9fbffc180a44795c98531d41ebd... file Active
4aa7b83b9d83db23b2a3dbfb6078a866928fc61655d0bc8... file Active
4c31d578ad4bac892f0dcb307080f24196360765fe007c3... file Active
4dc210da4efc55c32442a87eeeb3c45fc1e4001a9953650... file Active
563cb8c26e7a5867f24f3ba21ad1d7cf923703e02788a96... file Active
57594c0ebdf7365f6ccd6a576f32870e14bd87e627789de... file Active
59845f9e4a5ad158c9021dbe7dcdec5ec7fe388549c01ca... file Active
5b266c9bd119725dda27c91c08dd3b61659f2b91a487b42... file Active
5d38e81de505e6eeb887e10566ac09796db4bfeb9f4c130... file Active
5dc6318d8d50fb903ee4a79080769fd25a04ec6633cab32... file Active
5f6b65a372bfe982bca49e99f1ba17a57cbb5976a007bc0... file Active
631ddce47e2af455dcd985eb5f5e3fd8319b16b3db97b8e... file Active
6381ea65b83ea2e2a4eed2c9f6fe6c2b0e31d4df2daf820... file Active
65dbdc04b1574683304457cd7c78541ead165201f89a1b2... file Active
72d34977b8f4b4734e89da4a1e8a9468173b69364ebf615... file Active
73808dc4480bf696a4abc90c41b988886a6fa749c0b5609... file Active
81891ec2d391fb3ef95f04aa7c13cd99a7c4f939fec7ccd... file Active
8f8f61f95649f523e12533051dd55dd0d4da84da56873cb... file Active
9482dccd63983272e610041d4bbf262b9e2ac23d721c097... file Active
97684ae157687ede7bf91bebe6d495da66e8496c0c27325... file Active
98121e22dcb0b5ff2a05e49072b623ffd497b08c655ad20... file Active
9936afc821410d4ee8cc0a3d0bce6ef6b490392f4f13ae3... file Active
a00f249d4d86941b2b2d66c3431467ae8abac4ef8111c3b... file Active
b11676e7e98d54c983b87a6e69054e70670169bdba0bf44... file Active
b351a8b608f6e223ad8afd75d2f7121a4c7eec04ae1fd50... file Active
b3f05948bdcff16464125fbb87bd6dab3b55510b8ed093a... file Active
c1566f52e2f69008aa9afd6ea9a82972bdf2a51d90a7a85... file Active
c3bff052096f85673dcbdf9038114d55b9a7b9b84b4049c... file Active
c495527a844ddb6220ec8c333477e8d630b7552db38082a... file Active
cadac6b80362ccc22e5f25ec1c57c43d66c893539306193... file Active
d1f4dfba13d5407d367a847f213826f3a434e7af8f3daae... file Active
d437b362e0bade3bdbb0e0e729b28b0068225671eda83df... file Active
dd607c9a74ce0183b94b06e550f77814678c23cb11c6784... file Active
e880481a7a40b7b13dc50241646d64a61814c11f0e7edb6... file Active
ea0762fbdd49c6be02ef533ca14c8f33303ce21f3510ab1... file Active
edff8ce767dcec6300e05e7eb0712ab25673571503c2ac6... file Active
efc1fc9efefb96e31f887681bcdea337c3ab3312b4d55c7... file Active
effddfe0e246b069f48e91e03dcd361998b773283834d9e... file Active
f0b828e78df7156fd9213947c1542e9aedcb797595da537... file Active
f0cd9e36e2cdf45e59efab2761d606debd085fb7a6477b8... file Active
f566e89c45af2300900a522ab004bb1ac1a63301f4dac99... file Active
f97d74ac49a75219ac40e8612a0ec0a829ed9daac2d9132... file Active
fd07ef316187f311bec7d2ff9eb793cc3886463ebae9445... file Active
093b72e9b4efcc30c1644a763697a235c9c3e496c421ece... file Active
67e38438759f34eaf50d8b38b6c8f18155bcc08a2e79066... file Active
93d380ba2bedd37c2313924784b26fec27c9e96e4c500b5... file Active
6c2edf195ea849993dbccfe22200ac9c2549d96f8e0678f... file Active
265572824dd5f1b60f971255ad2555e4381bd6d3440f212... file Active
Indicators of compromise Indicators of compromise
IOC Threat Activity

Last 30 days

Chg

Avg 0