{"cveID":"CVE-2022-22965","vendorProject":"VMware","product":"Spring Framework","vulnerabilityName":"Spring Framework JDK 9+ Remote Code Execution Vulnerability","dateAdded":"2022-04-04","shortDescription":"Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-04-25","knownRansomwareCampaignUse":"Unknown","notes":"https://nvd.nist.gov/vuln/detail/CVE-2022-22965","cwes":["CWE-94"],"year":2022,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2022-22965","technique":"T1190","technique_name_at_mapping":"Exploit Public-Facing Application","mapping_type":"exploitation_technique","capability_group":"code_execution","comments":"This remote code execution (RCE) vulnerability affects Spring MVC or Spring WebFlux applications running on JDK 9+ when deployed on Tomcat as a WAR file. This vulnerability can be exploited by a remote attacker via data binding, allowing malicious actors to execute arbitrary code. Specifically, it has been used to deploy and execute the Mirai botnet malware. The exploit involves downloading a Mirai sample to the \"/tmp\" directory and changing its permissions to make it executable using \"chmod.\" The malware is then executed, enabling further malicious activities. The vulnerability does not affect applications deployed as Spring Boot executable jars. Observations of this exploit began in early April 2022, with malware variants available for different CPU architectures.","references":["https://www.trendmicro.com/en_us/research/22/d/cve-2022-22965-analyzing-the-exploitation-of-spring4shell-vulner.html"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2022-22965","technique":"T1059","technique_name_at_mapping":"Command and Scripting Interpreter","mapping_type":"primary_impact","capability_group":"code_execution","comments":"This remote code execution (RCE) vulnerability affects Spring MVC or Spring WebFlux applications running on JDK 9+ when deployed on Tomcat as a WAR file. This vulnerability can be exploited by a remote attacker via data binding, allowing malicious actors to execute arbitrary code. Specifically, it has been used to deploy and execute the Mirai botnet malware. The exploit involves downloading a Mirai sample to the \"/tmp\" directory and changing its permissions to make it executable using \"chmod.\" The malware is then executed, enabling further malicious activities. The vulnerability does not affect applications deployed as Spring Boot executable jars. Observations of this exploit began in early April 2022, with malware variants available for different CPU architectures.","references":["https://www.trendmicro.com/en_us/research/22/d/cve-2022-22965-analyzing-the-exploitation-of-spring4shell-vulner.html"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1059","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Command and Scripting Interpreter","name_at_mapping":"Command and Scripting Interpreter","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":95,"has_detection_strategy":true},{"id":"T1190","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploit Public-Facing Application","name_at_mapping":"Exploit Public-Facing Application","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":149,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 19:45 UTC","_attack_version":"19.2"}