CVE-2022-22978

In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.2.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.3.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*

History

11 Apr 2023, 23:15

Type Values Removed Values Added
References
  • {'url': 'https://tanzu.vmware.com/security/cve-2022-22978', 'name': 'https://tanzu.vmware.com/security/cve-2022-22978', 'tags': ['Vendor Advisory'], 'refsource': 'MISC'}
  • {'url': 'https://www.oracle.com/security-alerts/cpujul2022.html', 'name': 'N/A', 'tags': ['Patch', 'Third Party Advisory'], 'refsource': 'N/A'}
  • {'url': 'https://security.netapp.com/advisory/ntap-20220707-0003/', 'name': 'https://security.netapp.com/advisory/ntap-20220707-0003/', 'tags': ['Third Party Advisory'], 'refsource': 'CONFIRM'}
  • (MISC) https://spring.io/security/cve-2022-22978 -
Summary In Spring Security versions 5.5.6 and 5.6.3 and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

04 Feb 2023, 01:15

Type Values Removed Values Added
First Time Netapp active Iq Unified Manager
Netapp
Oracle
Oracle financial Services Crime And Compliance Management Studio
CPE cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.3.0:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.2.0:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
References (N/A) https://www.oracle.com/security-alerts/cpujul2022.html - (N/A) https://www.oracle.com/security-alerts/cpujul2022.html - Patch, Third Party Advisory
References (CONFIRM) https://security.netapp.com/advisory/ntap-20220707-0003/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20220707-0003/ - Third Party Advisory

25 Jul 2022, 18:20

Type Values Removed Values Added
References
  • (N/A) https://www.oracle.com/security-alerts/cpujul2022.html -

07 Jul 2022, 15:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20220707-0003/ -

02 Jun 2022, 16:30

Type Values Removed Values Added
CWE CWE-863
First Time Vmware
Vmware spring Security
CVSS v2 : unknown
v3 : unknown
v2 : 7.5
v3 : 9.8
CPE cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*
References (MISC) https://tanzu.vmware.com/security/cve-2022-22978 - (MISC) https://tanzu.vmware.com/security/cve-2022-22978 - Vendor Advisory

02 Jun 2022, 14:15

Type Values Removed Values Added
Summary In Spring Security versions 5.5.6 and 5.5.7 and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass. In Spring Security versions 5.5.6 and 5.6.3 and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass

19 May 2022, 15:35

Type Values Removed Values Added
New CVE

Information

Published : 2022-05-19 15:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-22978

Mitre link : CVE-2022-22978

CVE.ORG link : CVE-2022-22978


JSON object : View

Products Affected

netapp

  • active_iq_unified_manager

oracle

  • financial_services_crime_and_compliance_management_studio

vmware

  • spring_security
CWE
CWE-863

Incorrect Authorization