Java Spring Framework Exploit
Date: 2022-04-13
Author: Anders Adolfsson, Product Manager
Next >> Thales Versasec Webinar VSC
Previous << Yubico Versasec Webinar April 2022

Versasec would like to address questions and concerns that might surface with customers concerning the zero-day exploit affecting the Java Spring Framework disclosed on March 31, 2022.
The attack vector is not applicable to vSEC:CMS as it is currently explained in the RCE proof of concept. Versasec does not use Spring in the development process and Tomcat is not a part of the vSEC:CMS Server infrastructure.
For more information or questions, contact us on chat.