3.5
CVSSv2

CVE-2022-22970

Published: 12/05/2022 Updated: 07/10/2022
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.3 | Impact Score: 3.6 | Exploitability Score: 1.6
VMScore: 314
Vector: AV:N/AC:M/Au:S/C:N/I:N/A:P

Vulnerability Summary

In spring framework versions before 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware spring framework

oracle financial services crime and compliance management studio 8.0.8.2.0

oracle financial services crime and compliance management studio 8.0.8.3.0

netapp oncommand insight -

netapp active iq unified manager -

netapp brocade san navigator -

netapp cloud secure agent -

Vendor Advisories

Synopsis Important: Red Hat AMQ Broker 7103 release and security update Type/Severity Security Advisory: Important Topic Red Hat AMQ Broker 7103 is now available from the Red Hat Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, ...
Synopsis Important: Red Hat AMQ Broker 7110 release and security update Type/Severity Security Advisory: Important Topic Red Hat AMQ Broker 7110 is now available from the Red Hat Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, ...
Synopsis Important: Red Hat Fuse 7110 release and security update Type/Severity Security Advisory: Important Topic A minor version update (from 710 to 711) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Product Security has rated this update ...
In spring framework versions prior to 5320+ , 5222+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javaxservletPart to a field in a model object ...
A vulnerability (CVE-2022-22970) exists in Hitachi Ops Center Administrator and Hitachi Global Link Manager Affected products and versions are listed below Please upgrade your version to the appropriate version ...