Submitting forms on the support site are temporary unavailable for schedule maintenance. If you need immediate assistance please contact technical support. We apologize for the inconvenience.
Spring Framework vulnerability issue - CVE-2022-22965
Description
Spotlight products are not impacted by the Spring Framework Java related security issue - CVE-2022-22965
Cause
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
The following Spotlight products are not impacted by this security issue (CVE-2022-22965), since they do not use the Spring Framework.
Unaffected products:
Spotlight on SQL Server
Spotlight Cloud
Spotlight Tuning Pack
Spotlight on Oracle
Spotlight on SAP
Spotlight on DB2 LUW
NOTE
This is a "Quick Share" article provided by Quest Support. All content included in this article is unverified and provided “as is” for information purposes only. Although reasonable efforts have been made to present complete, current and accurate content, no guarantees for the completeness, currency or accuracy of this content is made. Accordingly, Quest makes no representation, warranty or endorsement of any kind regarding this content, whether express or implied, including but not limited to the implied warranties of satisfactory quality, fitness for a particular purpose, non-infringement, compatibility, security, accuracy or completeness.
Your Request will be reviewed by our technical reviewer team and, if approved, will be added as a Topic in our Knowledgebase.
Recommended Content
Product(s):
Spotlight Tuning Pack
Hosted
Spotlight Cloud
Hosted
Spotlight on SQL Server Enterprise
13.5.3
Spotlight on DB2
6.10, 6.9.3, 6.9.2
Spotlight on SAP ASE
2.12, 2.11, 2.10
Spotlight on Oracle
10.10, 10.9, 10.8
Topic(s):
Troubleshooting
Article History:
Created on: 4/4/2022 Last Update on: 4/14/2022
Author:
Edgar Ueno
Thank you for your feedback for Topic Request
Your Request will be reviewed by our technical reviewer team and, if approved, will be added as a Topic in our Knowledgebase.
Welcome to Quest Support
You can find online support help for Quest *product* on an affiliate support site. Click continue to be directed to the correct support content and assistance for *product*.
The Quest Software Portal no longer supports IE8, 9, & 10 and it is recommended to upgrade your browser to the latest version of Internet Explorer or Chrome.