Disclosure summary
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
Source-reported weakness categories
CWE-770
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2022-22970
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| vmware | spring_framework | * {"versionStartIncluding":"5.3.0","versionEndIncluding":"5.3.19"} |
| oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.2.0 |
| oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.3.0 |
| netapp | active_iq_unified_manager | - |
| netapp | active_iq_unified_manager | - |
| netapp | active_iq_unified_manager | - |
| netapp | brocade_san_navigator | - |
| netapp | cloud_secure_agent | - |
| netapp | oncommand_insight | - |
Original records & references
- NIST NVD record
- CVE Program record
- security.netapp.com — Third Party Advisory
- tanzu.vmware.com — Mitigation, Vendor Advisory
- www.oracle.com — Patch, Third Party Advisory
- security.netapp.com — Third Party Advisory
- tanzu.vmware.com — Mitigation, Vendor Advisory
- www.oracle.com — Patch, Third Party Advisory
PUBLISHED 2022-05-12T16:15:15-04:00
MODIFIED 2026-10-08T17:17:44-04:00
INGESTED 2026-10-10T20:50:21-04:00