Two critical vulnerabilities in the Spring ecosystem exposed Java applications to remote code execution: CVE-2022-22965 in the Spring Framework, widely known as Spring4Shell, and CVE-2022-22963 in Spring Cloud Function. Spring4Shell abuses the framework’s data-binding mechanism under specific conditions—including JDK 9+, Apache Tomcat, vulnerable Spring Framework versions, and WAR deployment—to let attackers overwrite Tomcat logging configuration and drop a JSP web shell on the server.
The Spring Cloud Function issue, CVE-2022-22963, allows code injection through a crafted spring.cloud.function.routing-expression HTTP header that exploits Spring Expression Language (SpEL) to achieve remote code execution. Vendor and security reporting identified affected versions, published fixes and mitigations, and highlighted detection opportunities including exploit-related file hashes and generic security verdicts for spotting attempted compromise.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Securelist published technical analysis of CVE-2022-22965 (Spring4Shell) and CVE-2022-22963, describing exploitation conditions, affected versions, available fixes, and detection indicators including exploit-related MD5 hashes.
VMware published an advisory for CVE-2022-22963, a remote code execution flaw in Spring Cloud Function caused by malicious Spring Expression handling in routing functionality.
Wiz reported that approximately 63% of cloud environments in its dataset contained resources affected by CVE-2022-22965 (Spring4Shell); roughly 75% of those resources were virtual machines and 25% were containers. It assessed known public exploitation as constrained by deployment prerequisites, with no publicly identified real-world targets meeting all known conditions apart from research demonstrations.
Praetorian reported that Spring Core deployments running on JDK 9 or later were vulnerable to remote code execution, the issue commonly known as Spring4Shell (CVE-2022-22965).
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
securelist.com
Open sourcewiz.io
Open sourcepraetorian.com
Open sourcetanzu.vmware.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.