CVE-2010-1622

Oracle Fusion Middleware < 2.5.7 - Code Injection

Title source: rule

Description

SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file.

Exploits (5)

exploitdb WRITEUP VERIFIED
by Meder Kydyraliev · textwebappsmultiple
https://www.exploit-db.com/exploits/13918
nomisec WORKING POC 19 stars
by DDuarte · poc
https://github.com/DDuarte/springshell-rce-poc
nomisec WORKING POC 2 stars
by E-bounce · poc
https://github.com/E-bounce/cve-2010-1622_learning_environment
nomisec STUB
by HandsomeCat00 · poc
https://github.com/HandsomeCat00/Spring-CVE-2010-1622
nomisec NO CODE
by strainerart · poc
https://github.com/strainerart/Spring4Shell

Scores

EPSS 0.0186
EPSS Percentile 83.1%

Details

CWE
CWE-94
Status published
Products (15)
oracle/fusion_middleware 7.6.2
oracle/fusion_middleware 11.1.1.6.1
oracle/fusion_middleware 11.1.1.8.0
org.springframework/spring 2.5.0 - 2.5.7Maven
springsource/spring_framework 2.5.0
springsource/spring_framework 2.5.1
springsource/spring_framework 2.5.2
springsource/spring_framework 2.5.3
springsource/spring_framework 2.5.4
springsource/spring_framework 2.5.5
... and 5 more
Published Jun 21, 2010
Tracked Since Feb 18, 2026