Technology

VMware critical vulnerability that is being actively exploited

VMware recently confirmed vulnerabilities in some VMware Tanzu developer tools. The Spring4Shell vulnerabilities were classified as critical. In addition to a workaround, the first updates are now available. Spring4Shell is a critical remote code execution vulnerability and is present in several VMware cloud computing and virtualization products. VMware products affected by Spring4Shell include the VMware Tanzu Application Service and Spring Boot.

A list of VMware products is available on the: Business support website available and added at the end of this post. In cases where no fix is ​​available, VMware has released a workaround to resolve the issue. VMware recommends that companies using the affected solutions act now, as Spring4Shell is an actively exploited vulnerability.

Vulnerability in the Spring Core Java framework

Spring4Shell, officially listed as CVE-2022-22965, is a vulnerability in the Spring Core Java Framework that can be exploited without authentication and has a severity rating of 9.8 out of 10. This means that any malicious actor with access to vulnerable applications could use arbitrary commands and take full control of a target system.

Proof of concept published

Due to the widespread use of the Spring Framework for developing Java applications, security analysts are already concerned about large-scale attacks that will exploit the Spring4Shell vulnerability. To make matters worse, a working proof-of-concept (PoC) exploit was released on GitHub before a security update was available. This, of course, increases the chances of malicious exploitation.

The affected versions of the applications are:

  • Spring Framework 5.3.18 and Spring Framework 5.2.20
  • Ferry Boot 2.5.12
  • Spring Boot 2.6.6 (coming soon)
  • VMware Tanzu Application Service for VMs – Versions 2.10 to 2.13
  • VMware Tanzu Operations Manager – versions 2.8 to 2.9
  • VMware Tanzu Kubernetes Grid Integrated Edition (TKGI) – versions 1.11 to 1.13

Recent Posts

Austin Fence Installation Contracts: 12 Clauses Homeowners Should Check in 2026

A fence proposal becomes useful only when it explains what will be built, who owns…

10 hours ago

Mouse for MMO players: Razer’s new Naga V3 Pro is a button monster

Razer is launching a new MMO mouse with the Naga V3 Pro. Three magnetic side…

1 day ago

Surface Phone: New images show discarded Microsoft prototype

It's an open secret that Microsoft was working on a Windows Phone smartphone long before…

1 day ago

How Solar Carport Structures Are Changing the Future of Sustainable Energy Infrastructure

As the demand for renewable energy continues to grow, businesses, municipalities, and property owners are…

1 day ago

What to do to find the right family law support in your case.

Family law issues seldom come at an opportune moment. Divorce, separation, parenting conflicts, child support,…

1 day ago

Claude AI data leak: Private chats were freely accessible on Google

Due to an insufficiently protected sharing function, private chat logs from the Anthropic AI Claude…

2 days ago