{"id":"CVE-2022-22970","title":"In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field…","summary":"In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-770","CWE-770"],"vendor":"vmware","product":"spring_framework","affected":["spring_framework <= 5.2.21","spring_framework >= 5.3.0, <= 5.3.19","financial_services_crime_and_compliance_management_studio = 8.0.8.2.0","financial_services_crime_and_compliance_management_studio = 8.0.8.3.0","active_iq_unified_manager","brocade_san_navigator","cloud_secure_agent","oncommand_insight"],"published":"2022-05-12","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:17:44.560","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-22970","references":[{"url":"https://security.netapp.com/advisory/ntap-20220616-0006/","label":"security@vmware.com"},{"url":"https://tanzu.vmware.com/security/cve-2022-22970","label":"security@vmware.com"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"security@vmware.com"},{"url":"https://security.netapp.com/advisory/ntap-20220616-0006/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://tanzu.vmware.com/security/cve-2022-22970","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.01962,"epssPercentile":0.79714,"exploits":{"github":1,"githubRepos":["https://github.com/Performant-Labs/CVE-2022-22970"],"checkedAt":"2026-10-08T22:12:30.003Z"},"exploitAvailable":true,"ingestedAt":"2026-10-08T22:11:53.750Z","slug":"CVE-2022-22970","body":"## Overview\n\nIn spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.\n\n## Affected\n\n- `spring_framework <= 5.2.21`\n- `spring_framework >= 5.3.0, <= 5.3.19`\n- `financial_services_crime_and_compliance_management_studio = 8.0.8.2.0`\n- `financial_services_crime_and_compliance_management_studio = 8.0.8.3.0`\n- `active_iq_unified_manager`\n- `brocade_san_navigator`\n- `cloud_secure_agent`\n- `oncommand_insight`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":29.2,"likelihood":0.4,"exploitation":12,"ransomware":0},"changes":[]}