« Volver al listado

CVE-2022-22968

Estado: ModificadaMedia (5.3)—

In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (7)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-22968",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Spring Framework",
          "versions": [
            {
              "status": "affected",
              "version": "Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-04-14T21:15:08.643",
  "references": [
    {
      "url": "https://security.netapp.com/advisory/ntap-20220602-0004/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "https://tanzu.vmware.com/security/cve-2022-22968",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "https://www.oracle.com/security-alerts/cpujul2022.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20220602-0004/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://tanzu.vmware.com/security/cve-2022-22968",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.oracle.com/security-alerts/cpujul2022.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-178"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path."
    },
    {
      "lang": "es",
      "value": "En Spring Framework versiones 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, y en las versiones anteriores no soportadas, los patrones para disallowedFields en un DataBinder distinguen entre mayúsculas y minúsculas, lo que significa que un campo no está efectivamente protegido a menos que aparezca con mayúsculas y minúsculas para el primer carácter del campo, incluyendo mayúsculas y minúsculas para el primer carácter de todos los campos anidados dentro de la ruta de la propiedad"
    }
  ],
  "lastModified": "2026-06-17T04:29:16.070",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "883A2633-B931-46F4-AA6F-FBB12E4D37C2",
              "versionEndExcluding": "5.2.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "35C1D09B-3ED6-401E-8F03-5042111335F5",
              "versionEndIncluding": "5.2.20",
              "versionStartIncluding": "5.2.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C95A124B-C603-41E6-934A-BBD33C45E19B",
              "versionEndIncluding": "5.3.18",
              "versionStartIncluding": "5.3.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F3E0B672-3E06-4422-B2A4-0BD073AEC2A1"
            },
            {
              "criteria": "cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A756737-1CC4-42C2-A4DF-E1C893B4E2D5"
            },
            {
              "criteria": "cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B55E8D50-99B4-47EC-86F9-699B67D473CE"
            },
            {
              "criteria": "cpe:2.3:a:netapp:cloud_secure_agent:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F0F202E8-97E6-4BBB-A0B6-4CA3F5803C08"
            },
            {
              "criteria": "cpe:2.3:a:netapp:metrocluster_tiebreaker:-:*:*:*:*:clustered_data_ontap:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B4A442CC-41F0-4DED-9D3C-89E58826E6A7"
            },
            {
              "criteria": "cpe:2.3:a:netapp:snap_creator_framework:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F4754FB-E3EB-454A-AB1A-AE3835C5350C"
            },
            {
              "criteria": "cpe:2.3:a:netapp:snapmanager:-:*:*:*:*:oracle:*:*",
              "vulnerable": true,
              "matchCriteriaId": "26A2B713-7D6D-420A-93A4-E0D983C983DF"
            },
            {
              "criteria": "cpe:2.3:a:netapp:snapmanager:-:*:*:*:*:sap:*:*",
              "vulnerable": true,
              "matchCriteriaId": "64DE38C8-94F1-4860-B045-F33928F676A8"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B0EBAC6D-D0CE-42A1-AEA0-2D50C8035747",
              "versionEndIncluding": "8.0.29"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@vmware.com"
}