CVE-2022-22965

Spring4Shell: stopped at runtime

Waratek RASP already blocks this exploit at runtime, inside the JVM - with no application change, no vendor patch, and no downtime.

Published April 1, 2022 · Updated March 4, 2026

Mitigated by Waratek CRITICAL CVSS 9.8 v3.1 Actively exploited

The vulnerability

Remote code execution via ClassLoader manipulation

Spring MVC and WebFlux applications on JDK 9+ can be tricked, through HTTP request-parameter data binding, into reaching the class loader of a bean. An attacker can rewrite Tomcat logging properties to drop and execute a web shell, achieving remote code execution against a WAR-deployed app.

Affected softwareSpring Framework (Spring MVC / Spring WebFlux)
Affected versions5.3.0 to 5.3.17 and 5.2.0 to 5.2.19 (and older, on JDK 9+)
WeaknessCode injection via data binding (CWE-94, CWE-74)
Published2022-04-01
SeverityCRITICAL · CVSS 9.8

Running an affected version? We can help.

Waratek RASP shields the vulnerable code in production - the exploit is blocked at runtime with no library upgrade, no redeploy, and no downtime. We can have you covered fast.

Talk to us about protection

How Waratek RASP stops it

Blocked at runtime by Waratek RASP

Waratek RASP ships a patch rule that blocks exploitation at the exact point the dangerous operation is attempted, inside the JVM.

Runtime, not perimeter

Waratek RASP acts inside the JVM at the exact call that turns input into code, so obfuscated and encoded payloads are caught where a WAF misses them.

No code changes

Protection is applied as a rule at runtime. No source edits, no recompilation, no library upgrade, and no application restart required.

Zero false positives

Rules target the specific unsafe behaviour of the exploit, so legitimate traffic keeps flowing while the attack is blocked and logged.

Flip one toggle in the Waratek Portal. The protection deploys to every attached application, with no restart.

Common questions

Spring4Shell FAQ

Is Spring4Shell (CVE-2022-22965) exploitable?

CVE-2022-22965 carries a CVSS 9.8/10 (CRITICAL) rating and affects Spring Framework (Spring MVC / Spring WebFlux) 5.3.0 to 5.3.17 and 5.2.0 to 5.2.19 (and older, on JDK 9+). Spring MVC and WebFlux applications on JDK 9+ can be tricked, through HTTP request-parameter data binding, into reaching the class loader of a bean. An attacker can rewrite Tomcat logging properties to drop and execute a web shell, achieving remote code execution against a WAR-deployed app. It is listed in CISA's Known Exploited Vulnerabilities catalog.

How does Waratek mitigate Spring4Shell (CVE-2022-22965)?

Waratek RASP blocks exploitation of Spring4Shell (CVE-2022-22965) inside the JVM at runtime, with no application code changes, no vendor patch and no restart.

How quickly was Spring4Shell (CVE-2022-22965) exploited after disclosure?

Exploit code for CVE-2022-22965 was already circulating publicly on March 30, 2022, before the vulnerability was even formally published in the NVD. Attackers had a head start before most defenders had a CVE record to react to.

Protect your apps in production

Get protected against Spring4Shell - without code changes or redeploying

Book a call and we’ll show you how Waratek RASP shields your running applications against CVE-2022-22965 and attacks like it, and get you covered in production.