Sploitus

Exploit for CVE-2022-22947

kitploit · 2026-08-26

Exploit Code

MARKDOWN33 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-CC3305-CVE-2022-22947
# CVE-2022-22947

> Ein Code-Injection-Angriff auf Spring Cloud Gateway

## Zusammenfassung der CVE

Bei Spring Cloud Gateway-Versionen vor 3.1.1+ und 3.0.7+ sind Anwendungen anfällig für einen Code-Injection-Angriff, wenn der Gateway-Actuator-Endpoint aktiviert, exponiert und ungesichert ist. Ein entfernter Angreifer könnte eine böswillig gestaltete Anfrage stellen, die eine beliebige Remote-Ausführung auf dem entfernten Host ermöglichen könnte.

## Betroffene Versionen

  * Oracle Commerce Guided Search 11.3.2
  * Oracle Communications Cloud Native Core Network Function Cloud Native Environment 1.10.0
  * Oracle Communications Cloud Native Core Console 22.2.0
  * Oracle Communications Cloud Native Core Network Slice Selection Function 1.8.0
  * Oracle Communications Cloud Native Core Network Slice Selection Function 22.1.0
  * Oracle Communications Cloud Native Core Security Edge Protection Proxy 22.1.1
  * Oracle Communications Cloud Native Core Network Repository Function 1.15.0
  * Oracle Communications Cloud Native Core Network Repository Function 1.15.1
  * Oracle Communications Cloud Native Core Network Repository Function 22.2.0
  * Oracle Communications Cloud Native Core Network Repository Function 22.1.2
  * Oracle Communications Cloud Native Core Binding Support Function 1.11.0
  * Oracle Communications Cloud Native Core Binding Support Function 22.1.3
  * Oracle Communications Cloud Native Core Service Communication Proxy 1.15.0
  * Oracle Communications Cloud Native Core Network Exposure Function 22.1.0
  * Vmware Spring Cloud Gateway < 3.0.7
  * Vmware Spring Cloud Gateway 3.1.0



## Referenzen

  * GitHub-POC - luckone, 02. März 2022