VDB
CVE-2024-22233
CVE-2024-22233
PUBLISHED
CVSS 8.699999809265137 HIGH
Es existiert eine Schwachstelle in VMware Tanzu Spring Framework. Diese, nicht näher beschriebene Schwachstelle besteht, wenn Spring MVC verwendet wird. Ein entfernter, anonymer Angreifer kann diese Schwachstelle unter bestimmten Umständen ausnutzen, um durch das Senden speziell gestalteter HTTP-Anfragen einen Denial of Service zu verursachen.
EPSS 1.54% · 81.7th percentile
Risk Scores
CVSS 4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS Score
1.54%
81.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Oracle Communications 24.1.0 | |
| Oracle | Oracle Communications 23.4.0 | |
| Gentoo | Gentoo Linux | |
| Oracle | Oracle Communications 14.0.0.0.0 | |
| Oracle | Oracle Communications 23.2.0 | |
| Oracle | Oracle Linux | |
| Oracle | Oracle Communications 23.3.0 | |
| Xerox | Xerox FreeFlow Print Server v9 | |
| Oracle | Oracle Communications 5.1 | |
| Oracle | Oracle Communications 23.1.0 | |
| Oracle | Oracle Communications 23.3.1 | |
| Oracle | Oracle Communications 5.2 | |
| Oracle | Oracle Communications 23.3.2 | |
| Oracle | Oracle Communications 23.4.1 | |
| Oracle | Oracle Communications <=23.4.2 | |
| Red Hat | Red Hat Enterprise Linux | |
| Oracle | Oracle Communications <=7.2.1.0.0 | |
| Oracle | Oracle Communications 22.4.0 | |
| Oracle | Oracle Communications 24.1.0.0.0 | |
| Oracle | Oracle Communications <=9.0.2 |
…and 4 more
Timeline
- Jan 21, 2024 CVE Published
- Jan 24, 2024 EPSS Score
- Feb 21, 2024 EPSS Score
- Mar 20, 2024 EPSS Score
- May 14, 2024 EPSS Score
- Jun 11, 2024 EPSS Score
- Jul 9, 2024 EPSS Score
- Aug 6, 2024 EPSS Score
- Sep 2, 2024 EPSS Score
- Sep 30, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Nov 25, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0170.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0170 advisory
- https://spring.io/security/cve-2024-22233 advisory
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0869.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0869 advisory
- https://www.oracle.com/security-alerts/cpuapr2024.html#AppendixCGBU advisory
- https://access.redhat.com/errata/RHSA-2024:1878 advisory
- https://security.gentoo.org/glsa/202405-01 advisory
- https://access.redhat.com/errata/RHSA-2024:7987 advisory
- https://securitydocs.business.xerox.com/wp-content/uploads/2024/11/Xerox-Security-Bulletin-XRX24-017-for-Xerox%C2%AE-FreeFlow%C2%AE-Print-Server-v9.pdf advisory
- https://linux.oracle.com/errata/ELSA-2025-15608.html advisory