---
id: CVE-2022-22970
title: >-
  In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported
  versions, applications that handle file uploads are vulnerable to DoS attack
  if they rely on data binding to set a MultipartFile or javax.servlet.Part to a
  field…
summary: >-
  In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported
  versions, applications that handle file uploads are vulnerable to DoS attack
  if they rely on data binding to set a MultipartFile or javax.servlet.Part to a
  field…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
  - CWE-770
vendor: vmware
product: spring_framework
affected:
  - spring_framework <= 5.2.21
  - 'spring_framework >= 5.3.0, <= 5.3.19'
  - financial_services_crime_and_compliance_management_studio = 8.0.8.2.0
  - financial_services_crime_and_compliance_management_studio = 8.0.8.3.0
  - active_iq_unified_manager
  - brocade_san_navigator
  - cloud_secure_agent
  - oncommand_insight
published: '2022-05-12'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:44.560'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-22970'
references:
  - url: 'https://security.netapp.com/advisory/ntap-20220616-0006/'
    label: security@vmware.com
  - url: 'https://tanzu.vmware.com/security/cve-2022-22970'
    label: security@vmware.com
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: security@vmware.com
  - url: 'https://security.netapp.com/advisory/ntap-20220616-0006/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://tanzu.vmware.com/security/cve-2022-22970'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.01962
epssPercentile: 0.79714
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/Performant-Labs/CVE-2022-22970'
  checkedAt: '2026-10-08T22:12:30.003Z'
exploitAvailable: true
ingestedAt: '2026-10-08T22:11:53.750Z'
---

## Overview

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

## Affected

- `spring_framework <= 5.2.21`
- `spring_framework >= 5.3.0, <= 5.3.19`
- `financial_services_crime_and_compliance_management_studio = 8.0.8.2.0`
- `financial_services_crime_and_compliance_management_studio = 8.0.8.3.0`
- `active_iq_unified_manager`
- `brocade_san_navigator`
- `cloud_secure_agent`
- `oncommand_insight`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
