---
id: CVE-2022-22971
title: >-
  In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported
  versions, application with a STOMP over WebSocket endpoint is vulnerable to a
  denial of service attack by an authenticated user.
summary: >-
  In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported
  versions, application with a STOMP over WebSocket endpoint is vulnerable to a
  denial of service attack by an authenticated user.
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
  - CWE-770
vendor: vmware
product: spring_framework
affected:
  - 'spring_framework >= 5.2.0, <= 5.2.21'
  - 'spring_framework >= 5.3.0, <= 5.3.19'
  - financial_services_crime_and_compliance_management_studio = 8.0.8.2.0
  - financial_services_crime_and_compliance_management_studio = 8.0.8.3.0
  - cloud_secure_agent
  - oncommand_insight
published: '2022-05-12'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:16.423'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-22971'
references:
  - url: 'https://security.netapp.com/advisory/ntap-20220616-0003/'
    label: security@vmware.com
  - url: 'https://tanzu.vmware.com/security/cve-2022-22971'
    label: security@vmware.com
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: security@vmware.com
  - url: 'https://security.netapp.com/advisory/ntap-20220616-0003/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://tanzu.vmware.com/security/cve-2022-22971'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.03174
epssPercentile: 0.87656
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/tchize/CVE-2022-22971'
  checkedAt: '2026-10-08T23:17:21.758Z'
exploitAvailable: true
ingestedAt: '2026-10-08T23:16:47.343Z'
---

## Overview

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

## Affected

- `spring_framework >= 5.2.0, <= 5.2.21`
- `spring_framework >= 5.3.0, <= 5.3.19`
- `financial_services_crime_and_compliance_management_studio = 8.0.8.2.0`
- `financial_services_crime_and_compliance_management_studio = 8.0.8.3.0`
- `cloud_secure_agent`
- `oncommand_insight`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
