ALERT: Some images may not load properly within the Knowledge Base Article. If you see a broken image, please right-click and select 'Open image in a new tab'. We apologize for this inconvenience.

Spring4Shell ZERO-day exploit CVE-2022-22963 and CVE-2022-22965 vulnerability for CA Release Automation (Nolio)


Article ID: 238520


Updated On:


CA Release Automation - DataManagement Server (Nolio) CA Release Automation - Release Operations Center (Nolio) CA Release Automation Connector


Two CVE’s for New Spring4Shell Zero-Day Vulnerability:

- CVE-2022-22963: Remote code execution in Spring Cloud Function by malicious Spring Expression

 - CVE-2022-22965: Spring Framework RCE via Data Binding on JDK 9+


Is CA Release Automation (Nolio) impacted by this vulnerability?



This vulnerability is exploited by use of Spring Cloud Function. Nolio does not use Spring Cloud Function. 



There are a couple of prerequisites for exploiting this vulnerability. One of those prerequisites is using JDK9+. Nolio does not support/use JDK9+. Nolio uses JRE8+