Critical Vulnerabilities 2022 Incident #56 CVE-2022-22965

Spring4Shell (CVE-2022-22965)

Estimated Financial Impact
$50-200M
Blast Radius
CVSS 9.8; Mirai botnet exploitation within 24hrs

What Happened

A critical RCE vulnerability (CVSS 9.8) in the Spring Framework, the most widely-used Java web framework globally. Actively exploited within 24 hours of disclosure including deployment of Mirai botnet agents. CISA added it to the Known Exploited Vulnerabilities catalog immediately.

✓

Risk Guard: Caught

VULN_RECENT_FREQUENCY + maintainer health preconditions

Risk Guard Check Codes That Flag This Incident

VULN_RECENT_FREQUENCY

How Every Tool Performed

1 Caught 0 Partial 5 After damage 0 Missed
Tool Verdict Details
OSS Risk Guard Caught VULN_RECENT_FREQUENCY + maintainer health preconditions
Socket After damage Detects after CVE published
Snyk After damage CVE detection after publication; reactive not proactive
Sonatype (Nexus) After damage Detects after CVE published
Black Duck After damage Detects after CVE published
Endor Labs After damage CVE detection + reachability analysis after publication; reactive
← Heartbleed (CVE-2014-0160) Text4Shell (CVE-2022-42889) →