Apr 01, 2022

This content release contains a new check for Spring4Shell.

New
Copy link

  • Detect Spring4Shell (CVE-2022-22965) in your environment with an authenticated check for Unix-like systems and a remote (unauthenticated) check for all systems. The authenticated check reports on vulnerable versions of the Spring Framework found within WAR files. Please note that the unzip utility is required to be installed on systems being scanned for comprehensive coverage. The authenticated check is available immediately for Nexpose and InsightVM Scan Engines. For InsightVM customers, an upcoming Insight Agent release will add support for this check. To learn more about using checks to detect Spring4Shell, see Scan for Spring4Shell in the InsightVM documentation.