Security Advisories / Bulletins / vendors Responses linked to Spring4Shell (CVE-2022-22965)
Errors, typos, something to say ?
- If you want to add a link, comment or send it to me
- Feel free to report any mistake directly below in the comment or in DM on Twitter @SwitHak
Other great resources
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
0-9
A
https://kb.acronis.com/fr/node/70402
Acronis :https://www.acunetix.com/blog/web-security-zone/critical-alert-spring4shell-rce-cve-2022-22965-in-spring/
Acunetix :https://addigy.com/blog/spring4shell-statement/
Addigy :https://discuss.aerospike.com/t/cve-2022-22965-spring4shell-rce-analysis/9310
Aerospike :https://docs.appdynamics.com/display/PAA/Security+Advisory%3A+Apache+Log4j+Vulnerability
AppDynamics :https://community.appian.com/support/w/kb/2626/kb-2209-information-about-the-spring4shell-security-vulnerability-cve-2022-22965
Appian :https://www.armory.io/blog/cve-2022-22965-spring-rce-which-does-not-impact-spinnaker/
Armory :https://arcticwolf.com/resources/blog/spring4shell
Artic Wolf :https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-006.txt
Aruba :Atlassian
https://community.developer.atlassian.com/t/attention-cve-2022-22965-spring-framework-rce-investigation/57172
Generic :https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631499/ReleaseNotes#4.1.6-(March-31,-2022)
Shibboleth :https://status.msi.audi.com/
Audi MSI :https://support.avaya.com/helpcenter/getGenericDetails?detailId=1399847128146
Avaya :B
https://blog.barracuda.com/2022/04/04/spring-framework-and-spring-cloud-function-vulnerabilities-what-you-need-to-know/
Barracuda :https://communities.bentley.com/products/projectwise/f/projectwise-di-forum/227933/zero-day-vulnerability-discovered-in-java-spring-framework-aka-spring4shell-similar-to-log4shell-does-this-affect-projectwise-in-any-capacity/705672#705672
Bentley :https://forum.bigfix.com/t/spring-framework-rce-vulnerability-current-bigfix-actions/41216
BigFix :https://docs.bitnami.com/azure/security/security-2022-03-31/
Bitnami :https://community.blueprism.com/communities/community-home/digestviewer/viewthread?GroupId=145&MessageKey=689f5600-1b0d-4a4b-a391-dbca90b86ede
BluePrism :https://www.blueriq.com/actueel/maatregelen-cve22950-22963-22965
Blueriq :https://bmcsites.force.com/casemgmt/sc_KnowledgeArticle?sfdcid=000395541
BMC :Broadcom
https://knowledge.broadcom.com/external/article?articleId=238270
CA :https://knowledge.broadcom.com/external/article/238526/spring4shell-zeroday-exploit-cve20222296.html
CA App :C
https://forum.camunda.org/t/spring-remote-code-execution-rce-vulnerability-spring4shell/33848
CAMUNDA :https://cpp.canon/spring4shell-vulnerability/
Canon Printing :https://blog.checkpoint.com/2022/04/05/16-of-organizations-worldwide-impacted-by-spring4shell-zero-day-vulnerability-exploitation-attempts-since-outbreak/
CheckPoint :https://blog.talosintelligence.com/2022/03/threat-advisory-spring4shell.html
Cisco Talos :Cisco
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67
GENERIC :https://bst.cisco.com/quickview/bug/CSCwb43658
AST :https://support.claris.com/s/article/Claris-FileMaker-products-and-the-Spring4Shell-vulnerability?language=en_US
Claris :https://www.cloudfoundry.org/blog/cve-2022-22965-uaa-affected-by-spring-framework-rce-via-data-binding-on-jdk-9/
Cloud Foundry Foundation :https://www.cloudsign.jp/info/20220401_information/
CloudSign :https://www.cm.com/blog/cmcom-response-to-zero-day-in-spring-core-framework/
CM.com :https://documentation.commvault.com/v11/essential/146231_security_vulnerability_and_reporting.html#cv2022041-spring-framework
Commvault :https://support.contrastsecurity.com/hc/en-us/articles/5202764027796#h_01FQ01JSF19SZ3BBDZ5PTZX5MC
ContrastSecurity :https://community.microfocus.com/cyberres/b/sws-22/posts/summary-of-cyberres-impact-from-spring4shell
Cyberes :D
https://www.datto.com/blog/dattos-response-to-spring4shell
Datto :https://security-tracker.debian.org/tracker/CVE-2022-22965
Debian :https://www.dell.com/support/kbdoc/fr-fr/000198134/vplex-vs2-vplex-vs6-false-positive-security-vulnerabilities-springshell
DELL :https://community.dhis2.org/t/dhis2-patch-release-2-35-13-is-now-available-security-hotfix/46791
DHIS2 :https://www.dynatrace.com/news/security-alert/spring-framework-rce-springshell-cve-2022-22965/
DynaTrace :E
https://helpdesk.egnyte.com/hc/en-us/articles/5291471550093-Spring4Shell-Zero-Day-Vulnerability-CVE-2022-22965-Update
Egnyte :https://enovationgroup.com/nl/nieuws/spring4shell-vulnerability-cve-2022-22965/
Enovation :https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/spring-framework-rce-vulnerabilities/
ESRI :https://forum.eset.com/topic/31966-spring4shell-rce-vulnerability-cve-2022-22965-eset-protect-webconsole-component/
ESET :https://joinup.ec.europa.eu/collection/e-government-innovation-center-egiz/solution/moa-id/news/status-moa-id-spring4shell-cve-2022-22965
EU E-ID :https://help.extensis.com/hc/en-us/articles/5102289148955-Portfolio-and-Spring4Shell-Vulnerabilities
Extensis :https://extremeportal.force.com/ExtrArticleDetail?an=000103717
ExtremeNetworks :F
https://support.f5.com/csp/article/K11510688
F5 Networks :https://community.flexera.com/t5/FlexNet-Publisher-Knowledge-Base/Spring4Shell-CVE-2022-22963-amp-CVE-2022-22950-impact-on-FlexNet/ta-p/229892/jump-to/first-unread-message
Flexera :https://community.theforeman.org/t/is-cve-2022-22965-an-issue-for-foreman/28001
Foreman :https://backstage.forgerock.com/knowledge/kb/article/a21709600
ForgeRock :https://www.fortiguard.com/psirt/FG-IR-22-072
Fortinet :G
https://digitalsupport.ge.com/en_US/Alert/GE-Security-Advisories
GE (Look for ID 000022074) :https://geoserver.org/announcements/vulnerability/2022/04/01/spring.html
Geoserver :https://about.gitlab.com/blog/2022/04/07/updates-regarding-spring-rce-vulnerabilities/
GitLab :https://www.ontotext.com/blog/graphdb-and-cve-2022-22965-aka-spring4shell/
GraphDB :H
https://www.haproxy.com/fr/blog/april-2022-cve-2022-22965-spring4shell-remote-code-execution-mitigation/
HapProxy :https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0097763
HCL :https://knowledge.hitachivantara.com/Security/%22Spring4Shell%22_-_RCE_Vulnerability_in_Spring_Framework_(CVE_2022-22965)
HitachiVantara :https://hyperproof.io/resource/spring4shell/
Hyperproof :I
https://community.ifs.com/framework-experience-infrastructure-cloud-integration-dev-tools-50/spring4shell-cve-2022-22965-20324
IFS :https://www.intercomstatus.com/incidents/7p27hqny602p
Intercom :https://support.intershop.com/sws/
Intershop :https://www.invicti.com/blog/web-security/understanding-your-spring-4-shell-risk/
Invicti :J
https://community.jamf.com/t5/jamf-pro/spring4shell-vulnerability/td-p/262584
Jamf :https://community.jaspersoft.com/wiki/java-spring-framework-vulnerability-update-jaspersoft-products
Jaspersoft :https://www.jenkins.io/blog/2022/03/31/spring-rce-CVE-2022-22965/
Jenkins :https://youtrack.jetbrains.com/issue/TW-75604
Jetbrains :https://jfrog.com/blog/springshell-zero-day-vulnerability-all-you-need-to-know/
JFROG :K
https://sourceforge.net/p/keepass/discussion/329220/thread/5234c16452/?limit=25
Keypass :https://knowledge.kofax.com/General_Support/General_Troubleshooting/Kofax_products_and_Spring4Shell_vulnerability_information
Kofax :https://www.konicaminolta.fr/fr-fr/news/bulletin-de-securite-faille-critique-spring-4-shell
Konica Minolta :L
https://www.landdata.de/neuigkeiten/sicherheitsluecke-spring4shell
LandData :https://www.lansweeper.com/forum/yaf_postst21117_Spring4Shell-and-Lansweeper.aspx#post67257
LanSweeper :https://support.laserfiche.com/kb/1014369/spring-framework-vulnerabilities-cve-2022-22965-cve-2022-22963-cve-2022-22947
LaserFiche :https://knowledge.liveperson.com/whats-new/spring4shell-a-java-spring-framework-remote-code-execution-vulnerability/
Liveperson :M
https://pitstop.manageengine.com/portal/en/community/topic/spring4shell-rce-vulnerability-cve-2022-22965-all-you-need-to-know
ManageEngine :https://www.microfocus.com/en-us/about/product-security-response-center/cve-2022-22965-vulnerability
Microfocus :https://www.microsoft.com/security/blog/2022/04/04/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965/
Microsoft :https://community.microstrategy.com/s/article/MicroStrategy-s-response-to-the-Spring-Framework-Remote-Code-Execution-Vulnerability?language=en_US
MicroStrategy :N
https://security.netapp.com/advisory/ntap-20220331-0011/
Netapp :https://doc.nexusgroup.com/display/PUB/Spring4Shell+Vulnerability
Nexus :https://www.nuspire.com/blog/spring4shell-zero-day-attack-what-you-need-to-know/
Nuspire :https://nxlog.co/news/spring-framework-vulnerability-cve-2022-22965
NXLOG :O
https://learn.objectiflune.com/blog/security/statement-on-spring-mvc-webflux-vulnerability-cve-2022-22965/
ObjectifLune :https://www.objective.com.au/resources/blog-ongoing-investigation-into-springshell-vulnerability-and-mitigation-actions-for-objective-products
Objective :https://sec.okta.com/articles/2022/04/oktas-response-cve-2022-22965-spring4shell
Okta :https://www.onespan.com/support/security/psirt/advisories-responses/vulnerabilities-java-spring-framework-component-onespan-products
OneSPAN :https://www.opennms.com/en/blog/2022-04-01-opennms-springshell/
OpenNMS :opensearch-project/OpenSearch#2699
OpenSearch :https://help.optimal-systems.com/rw/en/index.html
Optimal Systems :https://community.oracle.com/mosc/discussion/4516594/two-vulnerabilities-discovered-in-spring-java-libraries-cve-2022-22963-and-spring4shell
Oracle :https://www.origina.com/blog/spring4shell-vulnerability-update-april-8-2022
Origina :https://www.oxygenxml.com/security/advisory/CVE-2022-22965.html
OxygenXML :P
https://security.paloaltonetworks.com/CVE-2022-22963
PaloAlto Networks :https://customer.precisely.com/s/article/Precisely-Software-Spring4Shell?language=en_US
Precisely :https://knowledgebase.progress.com/articles/Article/Is-iMacros-Vulnerable-to-CVE-2022-22965-Spring4Shell
Progress :https://kb.pulsesecure.net/articles/Pulse_Secure_Article/KB45126/?kA13Z000000L3sW
PulseSecure :https://www.ptc.com/en/support/article/cs366379?language=en&posno=1&q=CVE-2022-22965&source=search
PTC :Q
https://community.qlik.com/t5/Support-Updates-Blog/Qlik-s-Response-to-March-2022-Spring-Framework-Vulnerabilities/ba-p/1913992
Qlik :R
https://www.raytion.com/cve-2022-22965-communication.html
Raytion :https://access.redhat.com/security/cve/CVE-2022-22965
RedHat :https://www.ricoh-europe.com/news-events/news/notice-of-the-potential-impact-of-cve-2022-22963-and-spring4shell-vulnerability-cve-2022-22965-on-ricoh-products-and-services/
Ricoh :https://community.securid.com/t5/general-security-advisories-and/rsa-customer-advisory-spring-framework-spring4shell/ta-p/675246
RSA SecurID :S
https://www.sagecity.com/fr/sage-xrt-solutions/f/sage-xrt-solutions-annonces-informations-et-alertes/183601/faille-spring4shell-vulnerabilite-critique-dans-le-framework-spring
SAGE :https://community.sailpoint.com/t5/Community-Announcements/Spring-Framework-RCE-vulnerability-Spring4Shell-CVE-2022-22965/ba-p/212914
SailPoint :https://status.salesforce.com/generalmessages/884
Salesforce :https://userapps.support.sap.com/sap/support/knowledge/mimes/call.htm?number=3171058
SAP :https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1116003
ServiceNow :https://www.solarwinds.com/trust-center/security-advisories/spring4shell
SolarWinds :https://community.sonarsource.com/t/sonarqube-sonarcloud-and-spring4shell/60926
SonarSource :https://blog.sonatype.com/new-0-day-spring-framework-vulnerability-confirmed
SonaType :https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005
SonicWall :https://www.sophos.com/en-us/security-advisories/sophos-sa-20220401-spring-rce
Sophos :https://discussions.soti.net/thread/spring4shell
SOTI :https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement
Spring :https://www.suse.com/security/cve/CVE-2022-22965.html
SUSE :T
https://www.tibco.com/support/notices/spring-framework-vulnerability-update
TIBCO :https://www.tomsawyer.com/spring4shell-security-vulnerability
Tomsawyer :https://success.trendmicro.com/dcx/s/solution/000290773?language=en_US
Trend Micro:https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/trustwaves-action-response-cve-2022-22965-and-cve-2022-22963/
Trustwave :U
https://ubuntu.com/security/CVE-2022-22965
Ubuntu :https://community.ui.com/releases/Statement-Regarding-Spring-CVE-2022-22965-2022-22950-and-2022-22963-001/19b2dc6f-4c36-436e-bd38-59ea0d6f1cb5
UI :https://www.unidata.ucar.edu/blogs/news/entry/upgrade-tds-5-to-latest
Unidata :V
https://www.veritas.com/content/support/en_US/article.100052799
Veritas :https://support.vertigis.com/hc/fr/articles/4909747208082-Informations-sur-la-vuln%C3%A9rabilit%C3%A9-Spring4Shell-CVE-2022-22965
Vertigis :https://community.visma.com/t5/Driftinformation/Information-om-sarbarheten-kand-som-Spring4Shell/td-p/488563
VISMA :VMware
https://tanzu.vmware.com/security/cve-2022-22965
TANZU :https://kb.vmware.com/s/article/88203
Blockchain :W
https://www.wowza.com/community/t/spring-framework-cve-2022-22963-and-2022-22965/94781
Wowza :X
https://www.xmcyber.com/blog/xm-cyber-advisory-spring4shell-zero-day/
XM Cyber :Y
Z
https://blog.zimbra.com/2022/04/security-update-zimbra-not-vulnerable-to-recent-openssl-and-spring-rce-vulnerabilities/
Zimbra :https://www.zorgttp.nl/spring4shell-kwetsbaarheid-geen-impact-op-zorgttp-dienstverlening/
ZorgTTP :Errors, typos, something to say ?
- If you want to add a link, comment or send it to me
- Feel free to report any mistake directly below in the comment or in DM on Twitter @SwitHak
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-006.txt
-> ADDED, Thanks.