CVE-2022-22946
Published on: Not Yet Published
Last Modified on: 02/22/2023 05:46:00 PM UTC
Certain versions of Commerce Guided Search from Oracle contain the following vulnerability:
In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates.
- CVE-2022-22946 has been assigned by
secu[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 5.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | HIGH | NONE |
CVSS2 Score: 2.1 - LOW
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
LOCAL | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | PARTIAL | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
CVE-2022-22946: Spring Cloud Gateway HTTP2 Insecure TrustManager | Security | VMware Tanzu | tanzu.vmware.com text/html |
![]() |
Oracle Critical Patch Update Advisory - July 2022 | www.oracle.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Oracle | Commerce Guided Search | 11.3.2 | All | All | All |
Application | Oracle | Communications Cloud Native Core Binding Support Function | 22.1.3 | All | All | All |
Application | Oracle | Communications Cloud Native Core Console | 22.2.0 | All | All | All |
Application | Oracle | Communications Cloud Native Core Network Repository Function | 22.1.2 | All | All | All |
Application | Oracle | Communications Cloud Native Core Network Repository Function | 22.2.0 | All | All | All |
Application | Oracle | Communications Cloud Native Core Security Edge Protection Proxy | 22.1.1 | All | All | All |
Application | Vmware | Spring Cloud Gateway | 3.1.0 | All | All | All |
- cpe:2.3:a:oracle:commerce_guided_search:11.3.2:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:22.1.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_cloud_native_core_console:22.2.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:22.1.2:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:22.2.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:22.1.1:*:*:*:*:*:*:*:
- cpe:2.3:a:vmware:spring_cloud_gateway:3.1.0:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-22946 : In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP… twitter.com/i/web/status/1… | 2022-03-04 16:05:41 |
![]() |
CVE-2022-22946 | 2022-03-04 17:38:23 |