logo

Addressing the Spring4Shell and CVE-2022-22963 RCE vulnerabilities in cloud environments

ID: 4b206de2-4e3d-5470-a505-0c777727a5be

STIX ID: report--4b206de2-4e3d-5470-a505-0c777727a5be

Feed Name: Wiz Blog

Threat Score
75/100

Date Published: 2022-04-01

Date Updated: 2026-05-01

...
...

### Executive Summary This report details two critical RCE vulnerabilities affecting Spring Framework (CVE-2022-22965, “Spring4Shell”) and Spring Cloud Function (CVE-2022-22963), explains exploitation prerequisites and mitigations, provides detection and prioritization guidance for cloud environments (including Wiz scanning capabilities), and presents prevalence data indicating roughly 63% of cloud environments contain the Spring4Shell-vulnerable version though many instances may not be practically exploitable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.