CVE-2022-22950: Spring Framework Security Vulnerability
search cancel

CVE-2022-22950: Spring Framework Security Vulnerability

book

Article ID: 245392

calendar_today

Updated On:

Products

CA Identity Suite CA Identity Manager

Issue/Introduction

This article addresses inquiries regarding the impact of the Spring Framework security vulnerability, CVE-2022-22950, on the Broadcom Identity Manager (IDM) product.

Environment

  • Identity Manager
  • 14.5, 14.5.1, 15.x

Resolution

Broadcom Engineering has confirmed that Identity Manager is not vulnerable to CVE-2022-22950. The investigation determined the following:

  1. Architecture: Identity Manager does not utilize the SpEL (Spring Expression Language) classes or JAR files associated with this vulnerability.
  2. Security Design: The Identity Suite software incorporates the following defensive measures to prevent exploitation:
     
    • Strict file upload size restrictions.
    • Robust code validation protocols.

No action is required for Identity Manager as it is not impacted by this vulnerability.

 

Additional Information

The Identity Suite has been designed with file upload size restrictions, as well as code validation, to prevent exactly this type of vulnerability from being exploited within the software.