Get real-time updates on Telegram
CVE-2022-22971: spring framework from 5.2.0 (inclusive), through 5.2.21 (inclusive), from 5.3.0 (inclusive), through 5.3.19…
CVE-2022-22971. CVSS 3.1 base score 6.5 (MEDIUM, NVD). EPSS 0.03174 (percentile 0.87656), scored 2026-10-08.
Affected technology
spring framework · from 5.2.0 (inclusive), through 5.2.21 (inclusive)
vmware
spring framework · from 5.3.0 (inclusive), through 5.3.19 (inclusive)
vmware
financial services crime and compliance management studio · 8.0.8.2.0
oracle
financial services crime and compliance management studio · 8.0.8.3.0
oracle
cloud secure agent · Version not applicable in the source CPE
netapp
oncommand insight · Version not applicable in the source CPE
netapp
Spring Framework · Spring Framework versions 5.3.x prior to 5.3.20, 5.2.x prior to 5.2.22 and all old and unsupported versions
Vendor not specified by the source
Description’s affected range: versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint
Component: Not specified by the source
Attack conditions (NVD, CVSS 3.1): Network (remote) · Low privileges required · No user interaction required
What an attacker can do
NVD’s CVSS 3.1 assessment (base score 6.5/10) rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
- CWE
- CWE-770
- CCR priority
- 26.8 /100 (P4)
- CVSS 3.1
- 6.5 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H · NVD
- EPSS
- 0.03174 · percentile 0.87656 · 2026-10-08
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-09 03:13:32.966430+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2022-22971.html