CyberSec.Space Logo
Back to CVE Browser

CVE-2022-22947

πŸ”₯ Known Exploited (CISA KEV)CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2022-03-03
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.

Affected Platforms (CPE)

πŸ“¦
Vmware

Spring Cloud Gateway

< 3.0.7= 3.1.0
πŸ“¦
Oracle

Commerce Guided Search

= 11.3.2
πŸ“¦
Oracle

Communications Cloud Native Core Binding Support Function

= 1.11.0= 22.1.3
πŸ“¦
Oracle

Communications Cloud Native Core Console

= 22.2.0

References & Advisories

Related Security Intelligence Articles

Related Vulnerabilities