CVE-2022-22976
Estado: ModificadaMedia (5.3)—
Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to an integer overflow error. The default settings are not affected by this CVE.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.34%
- Percentil entre todas las CVEs puntuadas: 83
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- CWE-190
- CWE-190
Referencias
- https://security.netapp.com/advisory/ntap-20220707-0003/
- https://tanzu.vmware.com/security/cve-2022-22976
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://security.netapp.com/advisory/ntap-20220707-0003/
- https://tanzu.vmware.com/security/cve-2022-22976
- https://www.oracle.com/security-alerts/cpujul2022.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-22976",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@vmware.com",
"affectedData": [
{
"vendor": "n/a",
"product": "Spring Security",
"versions": [
{
"status": "affected",
"version": "Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions"
}
]
}
]
}
],
"published": "2022-05-19T15:15:08.000",
"references": [
{
"url": "https://security.netapp.com/advisory/ntap-20220707-0003/",
"tags": [
"Third Party Advisory"
],
"source": "security@vmware.com"
},
{
"url": "https://tanzu.vmware.com/security/cve-2022-22976",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "security@vmware.com"
},
{
"url": "https://www.oracle.com/security-alerts/cpujul2022.html",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "security@vmware.com"
},
{
"url": "https://security.netapp.com/advisory/ntap-20220707-0003/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://tanzu.vmware.com/security/cve-2022-22976",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.oracle.com/security-alerts/cpujul2022.html",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@vmware.com",
"description": [
{
"lang": "en",
"value": "CWE-190"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-190"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to an integer overflow error. The default settings are not affected by this CVE."
},
{
"lang": "es",
"value": "Spring Security versiones 5.5.x anteriores a 5.5.7, 5.6.x anteriores a 5.6.4 y versiones anteriores no soportadas, contienen una vulnerabilidad de desbordamiento de enteros. Cuando es usada la clase BCrypt con el máximo factor de trabajo (31), el codificador no lleva a cabo ninguna ronda salt, debido a un error de desbordamiento de enteros. La configuración por defecto no está afectada por esta CVE"
}
],
"lastModified": "2026-06-17T04:29:16.813",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5CDB5C51-8FAA-4138-893B-56F792637CFE",
"versionEndExcluding": "5.5.7",
"versionStartIncluding": "5.2.1"
},
{
"criteria": "cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A5D9A4E3-CC02-48FD-AD99-8DE89490B614",
"versionEndExcluding": "5.6.4",
"versionStartIncluding": "5.6.0"
},
{
"criteria": "cpe:2.3:a:vmware:spring_security:5.2.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D508FDA8-A5CC-42F7-A259-4B1FB5AE6D8D"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "55F091C7-0869-4FD6-AC73-DA697D990304"
},
{
"criteria": "cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.3.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D134C60-F9E2-46C2-8466-DB90AD98439E"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*",
"vulnerable": true,
"matchCriteriaId": "F3E0B672-3E06-4422-B2A4-0BD073AEC2A1"
},
{
"criteria": "cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*",
"vulnerable": true,
"matchCriteriaId": "3A756737-1CC4-42C2-A4DF-E1C893B4E2D5"
},
{
"criteria": "cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "B55E8D50-99B4-47EC-86F9-699B67D473CE"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@vmware.com"
}