---
id: CVE-2022-22968
title: >-
  In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older
  unsupported versions, the patterns for disallowedFields on a DataBinder are
  case sensitive which means a field is not effectively protected unless it is
  listed with b…
summary: >-
  In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older
  unsupported versions, the patterns for disallowedFields on a DataBinder are
  case sensitive which means a field is not effectively protected unless it is
  listed with b…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-178
vendor: vmware
product: spring_framework
affected:
  - spring_framework < 5.2.0
  - 'spring_framework >= 5.2.0, <= 5.2.20'
  - 'spring_framework >= 5.3.0, <= 5.3.18'
  - active_iq_unified_manager
  - cloud_secure_agent
  - metrocluster_tiebreaker
  - snap_creator_framework
  - snapmanager
  - mysql_enterprise_monitor <= 8.0.29
patched:
  - spring_framework 5.2.0
published: '2022-04-14'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:44.393'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-22968'
references:
  - url: 'https://security.netapp.com/advisory/ntap-20220602-0004/'
    label: security@vmware.com
  - url: 'https://tanzu.vmware.com/security/cve-2022-22968'
    label: security@vmware.com
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: security@vmware.com
  - url: 'https://security.netapp.com/advisory/ntap-20220602-0004/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://tanzu.vmware.com/security/cve-2022-22968'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.05666
epssPercentile: 0.92776
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/MarcinGadz/spring-rce-poc'
  checkedAt: '2026-10-08T22:12:30.003Z'
exploitAvailable: true
ingestedAt: '2026-10-08T22:11:53.749Z'
---

## Overview

In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path.

## Affected

- `spring_framework < 5.2.0`
- `spring_framework >= 5.2.0, <= 5.2.20`
- `spring_framework >= 5.3.0, <= 5.3.18`
- `active_iq_unified_manager`
- `cloud_secure_agent`
- `metrocluster_tiebreaker`
- `snap_creator_framework`
- `snapmanager`
- `mysql_enterprise_monitor <= 8.0.29`

## Remediation

Upgrade past the affected range:

- `spring_framework 5.2.0`
