{"id":"CVE-2022-22971","title":"In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.","summary":"In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-770","CWE-770"],"vendor":"vmware","product":"spring_framework","affected":["spring_framework >= 5.2.0, <= 5.2.21","spring_framework >= 5.3.0, <= 5.3.19","financial_services_crime_and_compliance_management_studio = 8.0.8.2.0","financial_services_crime_and_compliance_management_studio = 8.0.8.3.0","cloud_secure_agent","oncommand_insight"],"published":"2022-05-12","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:17:16.423","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-22971","references":[{"url":"https://security.netapp.com/advisory/ntap-20220616-0003/","label":"security@vmware.com"},{"url":"https://tanzu.vmware.com/security/cve-2022-22971","label":"security@vmware.com"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"security@vmware.com"},{"url":"https://security.netapp.com/advisory/ntap-20220616-0003/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://tanzu.vmware.com/security/cve-2022-22971","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.03174,"epssPercentile":0.87656,"exploits":{"github":1,"githubRepos":["https://github.com/tchize/CVE-2022-22971"],"checkedAt":"2026-10-08T23:17:21.758Z"},"exploitAvailable":true,"ingestedAt":"2026-10-08T23:16:47.343Z","slug":"CVE-2022-22971","body":"## Overview\n\nIn spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.\n\n## Affected\n\n- `spring_framework >= 5.2.0, <= 5.2.21`\n- `spring_framework >= 5.3.0, <= 5.3.19`\n- `financial_services_crime_and_compliance_management_studio = 8.0.8.2.0`\n- `financial_services_crime_and_compliance_management_studio = 8.0.8.3.0`\n- `cloud_secure_agent`\n- `oncommand_insight`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":35.8,"likelihood":0.6,"exploitation":12,"ransomware":0},"changes":[]}