article thumbnail

What is Spring4Shell? Detect and mitigate new zero-day vulnerabilities in the Java Spring Framework

Dynatrace

CVE recently published three new critical vulnerabilities in the Java Spring Framework, including one called Spring4Shell. Many applications are potentially affected, as Spring dominates the Java ecosystem , with 60% of developers using it in their main Java applications. Denial of Service in Spring Expressions: CVE-2022-22950.

Java 195
article thumbnail

InfoSec 2022 guide: How DevSecOps practices drive organizational resilience

Dynatrace

Open source code, for example, has generated new threat vectors for attackers to exploit. Considering open source software (OSS) libraries now account for more than 70% of most applications’ code base, this threat is not going anywhere anytime soon. Spring4Shell vulnerabilities expose Java Spring Framework apps to exploitation.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Trending Sources

article thumbnail

New critical vulnerability, CVE-2022-42889, in Apache Commons Text discovered (but no need to panic)

Dynatrace

A new critical remote code execution (RCE) vulnerability was disclosed on October 13, 2022. While some view CVE-2022-42889 as the next Log4Shell vulnerability , others see its impact as more limited. A remote code execution vulnerability is a cyberattack an attacker can remotely execute commands on a user’s computing device.

Java 229
article thumbnail

RSA 2022 guide: DevSecOps transformation with runtime vulnerability management

Dynatrace

At RSA 2022 , the theme is Transform. Software intelligence as code enables tailored observability, AIOps, and application security at scale – blog. See how Dynatrace enables organizations to apply observability, AIOps, and application security as code, thus helping to reduce app onboarding time.

Strategy 229
article thumbnail

Black Hat 2022 highlights zero-day attacks as key theme

Dynatrace

Zero-day attacks are a key theme at Black Hat 2022 , a security conference taking place August 6-11 in Las Vegas. Such tools can prevent bad actors from injecting malicious code into applications that are accessible to the outside world. Security as code demands proactive DevSecOps – blog. Learn how security improves DevOps.

DevOps 130
article thumbnail

The anatomy of the Spring4Shell vulnerability and how to prevent its effects—and those of similar vulnerabilities

Dynatrace

Spring4Shell is a critical vulnerability in the Spring Framework , which emerged in late March 2022. Because 60% of developers use Spring for their Java applications , many applications are potentially affected. With a critical CVSS rating of 9.8 , Spring4Shell leaves affected systems vulnerable to remote code execution (RCE).

Java 221
article thumbnail

Advance DevSecOps practices with a vulnerability management strategy

Dynatrace

At the annual conference Dynatrace Perform 2022, the theme is “Empowering the game changers.” The vulnerability is located in Log4j 2, an open-source Apache Java software used to run logging services in a host of front-end and backend applications. Perform 2022 conference coverage , check out our guide. For our complete?

Strategy 208