VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 18 hours ago
Reset
More filters (1)
Columns
Oracle product: Oracle Communications / Management (Spring Framework)
Overview 3 matches, all in RASP scope · 2 protected · 1 KEV · 2 public PoC · 1 CISA SSVC · 1 EPSS ≥ 0.5 · 0 disputed
3matches, all in RASP scope 2protected66.7% 1KEV33.3% 2public PoC66.7% 1CISA SSVC33.3% 1EPSS ≥ 0.533.3% 0disputed0.0%
Critical 1 33.3% High 0 0.0% Medium 2 66.7% Low 0 0.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 2 66.7% Rule in development 0 0.0% Mitigation candidate 1 33.3% No exploit published 0 0.0% No fix identified 0 0.0% Mitigated by environment configuration 0 0.0% Queued for review 0 0.0% Not applicable 0 0.0% Out of RASP scope 0 0.0% Rejected 0 0.0%
blocked by ARMR today 2 66.7% not blocked 1 33.3% not established 0 0.0% unrecorded 0 0.0%
Exploited in the wild 1 33.3% Working exploit published 0 0.0% Proof of concept only 0 0.0% Forecast only 0 0.0% No public exploit 2 66.7%
split by peak 1 / month
Unknown: 0None: 0Low: 0Medium: 2High: 0Critical: 1 Rejected: 0Out of RASP scope: 0Not applicable: 0Queued for review: 0Mitigated by environment configuration: 0No fix identified: 0No exploit published: 0Mitigation candidate: 1Rule in development: 0Protected by RASP: 2 unrecorded: 0not established: 0not blocked: 1blocked by ARMR today: 2 No public exploit: 2Forecast only: 0Proof of concept only: 0Working exploit published: 0Exploited in the wild: 1 April 2022: 1 CVE May 2022: 1 CVE June 2022: 0 CVEs July 2022: 0 CVEs August 2022: 0 CVEs September 2022: 0 CVEs October 2022: 0 CVEs November 2022: 0 CVEs December 2022: 0 CVEs January 2023: 0 CVEs February 2023: 0 CVEs March 2023: 0 CVEs April 2023: 1 CVE
Apr 22Jun 22Aug 22Oct 22Dec 22Feb 23Apr 23
3 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2023-20863 Medium 2023-04-13 Mitigation candidate No public exploit In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
CVE-2022-22971 Medium 2022-05-12 Protected by RASP No public exploit In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
CVE-2022-22965 Critical 2022-04-01 Protected by RASP Exploited in the wild A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.