Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Configuration 7 (hide)
|
30 Oct 2025, 19:56
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22965 - US Government Resource |
22 Oct 2025, 00:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 20:18
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 19:19
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
10 Apr 2025, 16:56
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.kb.cert.org/vuls/id/970766 - US Government Resource |
21 Nov 2024, 06:47
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| References | () http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.html - Exploit, Third Party Advisory, VDB Entry | |
| References | () http://packetstormsecurity.com/files/167011/Spring4Shell-Spring-Framework-Class-Property-Remote-Code-Execution.html - Third Party Advisory, VDB Entry | |
| References | () https://cert-portal.siemens.com/productcert/pdf/ssa-254054.pdf - Patch, Third Party Advisory | |
| References | () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005 - Third Party Advisory | |
| References | () https://tanzu.vmware.com/security/cve-2022-22965 - Mitigation, Vendor Advisory | |
| References | () https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67 - Third Party Advisory | |
| References | () https://www.oracle.com/security-alerts/cpuapr2022.html - Third Party Advisory | |
| References | () https://www.oracle.com/security-alerts/cpujul2022.html - Patch, Third Party Advisory |
18 Oct 2024, 19:52
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Oracle jdk
|
|
| CPE | cpe:2.3:a:oracle:jdk:*:*:*:*:*:*:*:* |
25 Jul 2022, 18:20
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
19 May 2022, 14:21
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:h:veritas:netbackup_appliance:4.0.0.1:maintenance_release3:*:*:*:*:*:* cpe:2.3:a:veritas:flex_appliance:2.0.2:*:*:*:*:*:*:* cpe:2.3:a:veritas:flex_appliance:2.1:*:*:*:*:*:*:* cpe:2.3:h:veritas:netbackup_appliance:4.1.0.1:maintenance_release2:*:*:*:*:*:* cpe:2.3:a:veritas:access_appliance:7.4.3.100:*:*:*:*:*:*:* cpe:2.3:h:veritas:netbackup_appliance:4.0.0.1:maintenance_release2:*:*:*:*:*:* cpe:2.3:a:veritas:flex_appliance:2.0:*:*:*:*:*:*:* cpe:2.3:h:veritas:netbackup_virtual_appliance:4.0.0.1:maintenance_release1:*:*:*:*:*:* cpe:2.3:h:veritas:netbackup_virtual_appliance:4.1.0.1:maintenance_release1:*:*:*:*:*:* cpe:2.3:h:veritas:netbackup_appliance:4.0.0.1:maintenance_release1:*:*:*:*:*:* cpe:2.3:a:veritas:flex_appliance:1.3:*:*:*:*:*:*:* cpe:2.3:h:veritas:netbackup_appliance:4.1.0.1:maintenance_release1:*:*:*:*:*:* cpe:2.3:a:veritas:access_appliance:7.4.3:*:*:*:*:*:*:* cpe:2.3:a:veritas:netbackup_flex_scale_appliance:2.1:*:*:*:*:*:*:* cpe:2.3:h:veritas:netbackup_appliance:4.1:*:*:*:*:*:*:* cpe:2.3:h:veritas:netbackup_virtual_appliance:4.1:*:*:*:*:*:*:* cpe:2.3:h:veritas:netbackup_virtual_appliance:4.0.0.1:maintenance_release3:*:*:*:*:*:* cpe:2.3:a:veritas:flex_appliance:2.0.1:*:*:*:*:*:*:* cpe:2.3:h:veritas:netbackup_virtual_appliance:4.0:*:*:*:*:*:*:* cpe:2.3:h:veritas:netbackup_virtual_appliance:4.0.0.1:maintenance_release2:*:*:*:*:*:* cpe:2.3:h:veritas:netbackup_virtual_appliance:4.1.0.1:maintenance_release2:*:*:*:*:*:* cpe:2.3:a:veritas:netbackup_flex_scale_appliance:3.0:*:*:*:*:*:*:* cpe:2.3:a:veritas:access_appliance:7.4.3.200:*:*:*:*:*:*:* cpe:2.3:h:veritas:netbackup_appliance:4.0:*:*:*:*:*:*:* |
|
| References | (MISC) http://packetstormsecurity.com/files/167011/Spring4Shell-Spring-Framework-Class-Property-Remote-Code-Execution.html - Third Party Advisory, VDB Entry |
10 May 2022, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Apr 2022, 14:40
| Type | Values Removed | Values Added |
|---|---|---|
| References | (MISC) https://www.oracle.com/security-alerts/cpuapr2022.html - Third Party Advisory | |
| References | (MISC) http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.html - Exploit, Third Party Advisory, VDB Entry | |
| References | (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-254054.pdf - Third Party Advisory | |
| CPE | cpe:2.3:a:oracle:communications_cloud_native_core_network_exposure_function:22.1.0:*:*:*:*:*:*:* cpe:2.3:a:siemens:siveillance_identity:1.5:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_policy_management:12.6.0.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_xstore_point_of_service:20.0.1:*:*:*:*:*:*:* cpe:2.3:a:siemens:sipass_integrated:2.80:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_cloud_native_core_console:22.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:22.1.0:*:*:*:*:*:*:* cpe:2.3:a:siemens:siveillance_identity:1.6:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.2.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:1.10.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:1.15.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.9.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.15.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.2.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.1.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:22.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:* cpe:2.3:a:siemens:sipass_integrated:2.85:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.8.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:sd-wan_edge:9.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:sd-wan_edge:9.1:*:*:*:*:*:*:* cpe:2.3:a:siemens:operation_scheduler:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.15.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.1.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:22.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_xstore_point_of_service:21.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.2.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:22.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_cloud_native_core_policy:22.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:22.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_cloud_native_core_console:1.9.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:22.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.15.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:1.7.0:*:*:*:*:*:*:* |
20 Apr 2022, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
19 Apr 2022, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
13 Apr 2022, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
08 Apr 2022, 17:43
| Type | Values Removed | Values Added |
|---|---|---|
| References | (CONFIRM) https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005 - Third Party Advisory | |
| References | (MISC) https://tanzu.vmware.com/security/cve-2022-22965 - Mitigation, Vendor Advisory | |
| References | (CISCO) https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67 - Third Party Advisory | |
| CWE | CWE-94 | |
| CVSS |
v2 : v3 : |
v2 : 7.5
v3 : 9.8 |
| CPE | cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:* cpe:2.3:a:cisco:cx_cloud_agent:*:*:*:*:*:*:*:* |
02 Apr 2022, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
02 Apr 2022, 03:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
01 Apr 2022, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2022-04-01 23:15
Updated : 2025-10-30 19:56
NVD link : CVE-2022-22965
Mitre link : CVE-2022-22965
CVE.ORG link : CVE-2022-22965
JSON object : View
veritas
- access_appliance
- netbackup_appliance
- flex_appliance
- netbackup_flex_scale_appliance
- netbackup_virtual_appliance
oracle
- retail_financial_integration
- jdk
- communications_cloud_native_core_network_function_cloud_native_environment
- communications_cloud_native_core_unified_data_repository
- financial_services_analytical_applications_infrastructure
- commerce_platform
- communications_cloud_native_core_network_repository_function
- weblogic_server
- sd-wan_edge
- communications_cloud_native_core_security_edge_protection_proxy
- communications_cloud_native_core_binding_support_function
- communications_cloud_native_core_automated_test_suite
- retail_integration_bus
- financial_services_behavior_detection_platform
- communications_unified_inventory_management
- retail_bulk_data_integration
- communications_cloud_native_core_network_exposure_function
- financial_services_enterprise_case_management
- communications_cloud_native_core_policy
- product_lifecycle_analytics
- communications_cloud_native_core_network_slice_selection_function
- retail_merchandising_system
- communications_policy_management
- retail_xstore_point_of_service
- mysql_enterprise_monitor
- retail_customer_management_and_segmentation_foundation
- communications_cloud_native_core_console
siemens
- simatic_speech_assistant_for_machines
- siveillance_identity
- sinec_network_management_system
- sipass_integrated
- operation_scheduler
cisco
- cx_cloud_agent
vmware
- spring_framework
Improper Control of Generation of Code ('Code Injection')
