IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

EDR: Is Sensor Vulnerable to CVE-2022-22965 (Spring4Shell)?

EDR: Is Sensor Vulnerable to CVE-2022-22965 (Spring4Shell)?

Environment

  • EDR Server: All Versions
  • EDR Sensor: All Versions

Question

Is the EDR Sensor vulnerable to CVE-2022-22965 (Spring4Shell)?

Answer

No, this vulnerability does not affect any VMware EDR products.

Additional Notes

  • Fixes and workarounds suggested: Upgrade to Spring Framework 5.3.18 and 5.2.20 in the next release.
  • Additional URL discussing issue: 

Labels (1)
Tags (2)
Was this article helpful? Yes No
100% helpful (2/2)
Article Information
Author:
Creation Date:
‎04-11-2022
Views:
442
Contributors