## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-CC3305-CVE-2022-22947
# CVE-2022-22947
> Ein Code-Injection-Angriff auf Spring Cloud Gateway
## Zusammenfassung der CVE
Bei Spring Cloud Gateway-Versionen vor 3.1.1+ und 3.0.7+ sind Anwendungen anfällig für einen Code-Injection-Angriff, wenn der Gateway-Actuator-Endpoint aktiviert, exponiert und ungesichert ist. Ein entfernter Angreifer könnte eine böswillig gestaltete Anfrage stellen, die eine beliebige Remote-Ausführung auf dem entfernten Host ermöglichen könnte.
## Betroffene Versionen
* Oracle Commerce Guided Search 11.3.2
* Oracle Communications Cloud Native Core Network Function Cloud Native Environment 1.10.0
* Oracle Communications Cloud Native Core Console 22.2.0
* Oracle Communications Cloud Native Core Network Slice Selection Function 1.8.0
* Oracle Communications Cloud Native Core Network Slice Selection Function 22.1.0
* Oracle Communications Cloud Native Core Security Edge Protection Proxy 22.1.1
* Oracle Communications Cloud Native Core Network Repository Function 1.15.0
* Oracle Communications Cloud Native Core Network Repository Function 1.15.1
* Oracle Communications Cloud Native Core Network Repository Function 22.2.0
* Oracle Communications Cloud Native Core Network Repository Function 22.1.2
* Oracle Communications Cloud Native Core Binding Support Function 1.11.0
* Oracle Communications Cloud Native Core Binding Support Function 22.1.3
* Oracle Communications Cloud Native Core Service Communication Proxy 1.15.0
* Oracle Communications Cloud Native Core Network Exposure Function 22.1.0
* Vmware Spring Cloud Gateway < 3.0.7
* Vmware Spring Cloud Gateway 3.1.0
## Referenzen
* GitHub-POC - luckone, 02. März 2022