logo

New Zero-day RCE Vulnerability Spring4Shell

ID: a2af9538-59dc-51bb-ad0d-b19335a9cb7d

STIX ID: report--a2af9538-59dc-51bb-ad0d-b19335a9cb7d

Feed Name: Aqua Security Blog

Threat Score
75/100

Date Published: 2022-03-31

Date Updated: 2026-04-26

...
...

A critical zero-day RCE (CVE-2022-22965, Spring4Shell) affecting Spring Framework on JDK9+ can be exploited when applications accept POJO parameters; exploit code can drop a web shell and execute arbitrary code with the Tomcat process privileges. The report covers the chaotic disclosure, confirmed active exploitation, available vendor patches, short-term mitigations (WAF, restricting DataBinder bindings), and detection/mitigation options via Aqua's scanning and runtime protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.