Skip to main content
dmaciejak
Staff
Staff
November 30, 2022

Outbreak Alert: VMWare Spring4Shell Vulnerability

  • November 30, 2022
  • 0 replies
  • 993 views
Description

This article describes detection of the Spring4Shell vulnerability with FortiDevSec.

 

The CVE-2022-22965 vulnerability is a 0-day exploit that was discovered on a popular Java lightweight open source framework named Spring Framework.

This zero-day can result in remote code execution, allowing the attacker to take full control of the target system.

Scope

FortiDevSec SCA scanner updated in version 22.4

Solution

Detection against the vulnerability is empowered by the FortiDevSec Software Composition Analysis (SCA) scanner.

 

This technology enables FortiDevSec to assess whether an application codebase is vulnerable to a specific vulnerability with a high level of confidence by identifying open-source software dependencies.

 

The SCA scanner is enabled by default. Once the scan is performed on an application, the result appears under the Software Composition Analysis tab.

 

A step-by-step guide on how to scan an application is available in the user guide.

 

For more details regarding mitigating the Spring4Shell vulnerability with Fortinet products, refer to https://www.fortiguard.com/outbreak-alert/spring4shell-vulnerability.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!