{"id":9120,"date":"2022-04-01T15:48:55","date_gmt":"2022-04-01T13:48:55","guid":{"rendered":"http:\/\/nfirjun2026.local\/this-spring4shell-flow-chart-helps-you-make-the-right-decisions\/"},"modified":"2023-03-01T21:44:02","modified_gmt":"2023-03-01T20:44:02","slug":"this-spring4shell-flow-chart-helps-you-make-the-right-decisions","status":"publish","type":"post","link":"https:\/\/www.cyber-security-online.nl\/en\/this-spring4shell-flow-chart-helps-you-make-the-right-decisions\/","title":{"rendered":"This Spring4Shell flow chart helps you make the right decisions"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"9120\" class=\"elementor elementor-9120 elementor-8768\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-06c4724 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"06c4724\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-fb77167\" data-id=\"fb77167\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-inner-section elementor-element elementor-element-cca9d26 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"cca9d26\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-b11f1dc\" data-id=\"b11f1dc\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-4a91542 elementor-widget elementor-widget-text-editor\" data-id=\"4a91542\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>In recent days, many organizations have asked for our help in making the right decisions around applications in response to the Spring4Shell vulnerability. More and more details are becoming known but far from everything is completely clear. Nevertheless, it is advised to take action as soon as possible and take the appropriate measures to prevent unauthorized access to your systems. To help you make the right decisions, we have developed a Spring4Shell flow chart for you. This flow chart will help you make the right choices with the information that is currently available. Given the developments, it is advisable to check this page and our <a href=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/04\/NFIR-Threat-Intelligence-Report-Indicaties-dat-kwetsbaarheid-Spring4Shell-CVE-2022-22965-mogelijk-actief-misbruikt-wordt.pdf\" target=\"_blank\" rel=\"noopener\"><br \/>\n  <strong>Threat Intelligence Report<\/strong><br \/>\n<\/a> regularly. This is because they are updated as soon as new information is available.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ef559c8 elementor-widget elementor-widget-heading\" data-id=\"ef559c8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Flowchart<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a4eec2f elementor-widget elementor-widget-image\" data-id=\"a4eec2f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/04\/Spring4Shell_vulnerability_flow_NFIR-NL.pdf\" target=\"_blank\">\n\t\t\t\t\t\t\t<img decoding=\"async\" width=\"1024\" height=\"729\" src=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/04\/Spring4Shell_vulnerability_flow_NFIR-NL-1.0-1024x729.png\" class=\"attachment-large size-large wp-image-8763\" alt=\"This Spring4Shell flow chart helps you make the right decisions\" srcset=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/04\/Spring4Shell_vulnerability_flow_NFIR-NL-1.0-1024x729.png 1024w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/04\/Spring4Shell_vulnerability_flow_NFIR-NL-1.0-300x213.png 300w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/04\/Spring4Shell_vulnerability_flow_NFIR-NL-1.0-768x546.png 768w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/04\/Spring4Shell_vulnerability_flow_NFIR-NL-1.0.png 1251w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/>\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-f4bff09\" data-id=\"f4bff09\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-996aa7a elementor-widget elementor-widget-image\" data-id=\"996aa7a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/www.cyber-security-online.nl\/en\/incident-response-specialist-24-7-availability\/\">\n\t\t\t\t\t\t\t<img decoding=\"async\" width=\"1251\" height=\"890\" src=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/04\/Spring4Shell_vulnerability_flow_NFIR-NL-1.0.png\" class=\"attachment-full size-full wp-image-8763\" alt=\"This Spring4Shell flow chart helps you make the right decisions\" srcset=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/04\/Spring4Shell_vulnerability_flow_NFIR-NL-1.0.png 1251w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/04\/Spring4Shell_vulnerability_flow_NFIR-NL-1.0-300x213.png 300w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/04\/Spring4Shell_vulnerability_flow_NFIR-NL-1.0-1024x729.png 1024w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/04\/Spring4Shell_vulnerability_flow_NFIR-NL-1.0-768x546.png 768w\" sizes=\"(max-width: 1251px) 100vw, 1251px\" \/>\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-49b2fd5 elementor-widget elementor-widget-button\" data-id=\"49b2fd5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/04\/Spring4Shell_vulnerability_flow_NFIR-NL.pdf\" target=\"_blank\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t<span class=\"elementor-button-icon\">\n\t\t\t\t<i aria-hidden=\"true\" class=\"far fa-file-pdf\"><\/i>\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Download the flowchart here (NL)<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-87d51fa elementor-widget elementor-widget-button\" data-id=\"87d51fa\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/04\/Spring4Shell_vulnerability_flow_NFIR-EN.pdf\" target=\"_blank\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t<span class=\"elementor-button-icon\">\n\t\t\t\t<i aria-hidden=\"true\" class=\"far fa-file-pdf\"><\/i>\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Download the flowchart here<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-a2565af elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"a2565af\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-73bc578\" data-id=\"73bc578\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-277a433 nfir-from-uael-faq nfir-faq-schema elementor-widget elementor-widget-accordion\" data-id=\"277a433\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"accordion.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-accordion\">\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-4131\" class=\"elementor-tab-title\" data-tab=\"1\" role=\"button\" aria-controls=\"elementor-tab-content-4131\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">Description:What is the Spring Core Framework?<\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-4131\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"1\" role=\"region\" aria-labelledby=\"elementor-tab-title-4131\">\n          <p>Spring Core Framework is a collection of Java software libraries that can be used in software programs written in Java. Spring Core is embedded in many Java software.<\/p>\n          <p>The vulnerability allows an attacker &#8211; without requiring authentication &#8211; to execute unauthorized code in certain circumstances and gain access to the program\/application and the information in that program\/application.<\/p>\n          <p> <\/p>\n          <p>To be able to abuse this vulnerability, several technical prerequisites are currently known, this list may not yet be complete.<\/p>\n          <p>As far as we know now, the application is vulnerable if it meets the following conditions:<\/p>\n          <ul>\n            <li>Uses Spring Core Framework (up to and including version 5.3.17);<\/li>\n            <li>Uses spring-webmvc or spring-webflux dependencies (unconfirmed)<\/li>\n            <li>Uses form bindings with &#8220;name=value&#8221; data.<\/li>\n            <li>Does not use an allowlist or denylist that excludes the use of specific fields (such as &#8220;class&#8221;, &#8220;module&#8221; and &#8220;classLoader&#8221;).<\/li>\n            <li>Runs on Java version 9 (JDK) or higher.<\/li>\n          <\/ul>\n          <p>In short: Applications that are remotely accessible, can process user input, and use Spring Core Framework (a version lower than 5.3.17) to process this input may be vulnerable.<\/p>\n        <\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-4132\" class=\"elementor-tab-title\" data-tab=\"2\" role=\"button\" aria-controls=\"elementor-tab-content-4132\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What potential impact does this vulnerability have?<\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-4132\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"2\" role=\"region\" aria-labelledby=\"elementor-tab-title-4132\">\n          <p>If an attacker is able to successfully exploit the vulnerability then it can lead to the execution of unauthorized code on the affected systems. This could potentially result in the server running the application becoming compromised. This attack can be performed from the Internet where no authentication is required.<\/p>\n          <p>From a compromised server, an attacker could potentially gain access to the rest of the network. For this reason, the CVSS vulnerability score was classified as <strong>critical<\/strong> (9.8).<\/p>\n        <\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-4133\" class=\"elementor-tab-title\" data-tab=\"3\" role=\"button\" aria-controls=\"elementor-tab-content-4133\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What are the Indications abuse of this vulnerability?<\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-4133\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"3\" role=\"region\" aria-labelledby=\"elementor-tab-title-4133\">\n          <p>At the time of writing, there are multiple indicators that there are active attempts to exploit the vulnerability &#8211; including attempts by known rogue IP addresses to exploit the vulnerability: <a href=\"https:\/\/otx.alienvault.com\/pulse\/6246c5778ca27726b90d842e\" target=\"_blank\" rel=\"noopener\">https:\/\/otx.alienvault.com\/pulse\/6246c5778ca27726b90d842e<\/a><\/p>\n        <\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-4134\" class=\"elementor-tab-title\" data-tab=\"4\" role=\"button\" aria-controls=\"elementor-tab-content-4134\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">How is it detectable?<\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-4134\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"4\" role=\"region\" aria-labelledby=\"elementor-tab-title-4134\">\n          <p>Because the vulnerable functionality resides in a popular Java software library which is widely used, the current scope or impact is not transparent. It is very likely that many used applications are vulnerable which are not known at the time of writing. The above makes fully detecting any abuse of the vulnerability, at the time of writing, complex.<\/p>\n          <p>However, a scanner has been published which may be able to detect the presence of the Spring Framework on (local) systems &#8211; this scanner is published via the code platform GitHub: <a href=\"https:\/\/github.com\/hillu\/local-spring-vuln-scanner\" target=\"_blank\" rel=\"noopener\">https:\/\/github.com\/hillu\/local-spring-vuln-scanner<\/a><\/p>\n        <\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-4135\" class=\"elementor-tab-title\" data-tab=\"5\" role=\"button\" aria-controls=\"elementor-tab-content-4135\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What are the recommendations?<\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-4135\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"5\" role=\"region\" aria-labelledby=\"elementor-tab-title-4135\">\n          <p>For developers of applications using Spring Framework, the following advice applies:  <br>A new version of Spring Framework is available which can be downloaded from the URL <strong>The recommendation is to at least update to <\/strong>Spring Framework version <strong>5.3.18<\/strong> (with Spring Boot <strong>2.6.6<\/strong> or <strong>2.5.12<\/strong>) or Spring Framework <strong>5.2.20<\/strong>.<\/p>\n          <p>NFIR recommends upgrading as soon as possible and then deploying to affected systems and applications.<\/p>\n          <p>\n            <em>At the point when upgrading is not possible, the following mitigation can be applied:<\/em>\n          <\/p>\n          <ol>\n            <li>For organizations that use Spring Framework itself and have specific bindings within applications that use non-standard data types, it is important to specify the allowed fields that the application may use &#8211; More information on this is available in the Spring Documentation: <a href=\"https:\/\/docs.spring.io\/spring-framework\/docs\/current\/javadoc-api\/org\/springframework\/validation\/DataBinder.html#:~:text=fields%20when%20binding.-,setAllowedFields,-public%C2%A0void%C2%A0setAllowedFields\" target=\"_blank\" rel=\"noopener\">https:\/\/docs.spring.io\/spring-framework\/docs\/current\/javadoc-api\/org\/springframework\/validation\/DataBinder.html#:~:text=fields20when20binding.-,setAllowedFields,-publicC2A0voidC2A0setAllowedFields<\/a><\/li>\n            <li>A second available mitigation (in the case that Tomcat is used as the underlying web server) involves updating Tomcat to versions 10.0.20, 9.0.62, and 8.5.78 (or higher) which will render the attack route via Tomcat inoperable. More information is available on the Spring website: <a href=\"https:\/\/spring.io\/blog\/2022\/04\/01\/spring-framework-rce-mitigation-alternative\" target=\"_blank\" rel=\"noopener\">https:\/\/spring.io\/blog\/2022\/04\/01\/spring-framework-rce-mitigation-alternative<\/a><\/li>\n          <\/ol>\n          <p>For third-party applications that you use, NFIR recommends that you contact the vendor for any updates.<\/p>\n        <\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-4136\" class=\"elementor-tab-title\" data-tab=\"6\" role=\"button\" aria-controls=\"elementor-tab-content-4136\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">Is there a plan of action?<\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-4136\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"6\" role=\"region\" aria-labelledby=\"elementor-tab-title-4136\">\n          <p>It is important for your organization to take at least the following steps:<\/p>\n          <ol>\n            <li>Map out which individual vendors you have for on-premises software packages, Software-as-a-Service (SaaS) or other application vendors;<\/li>\n            <li>Consult your vendor&#8217;s website and determine if there is some form of &#8216;dependency lists&#8217; available within which you can verify that &#8216;Spring Framework&#8217; is being used within the application;<\/li>\n            <li>Contact your vendors to verify if &#8216;Spring Framework&#8217; is used within the applications and which version of Spring Framework is used;<\/li>\n            <li>Prepare your organization for the situation when patches need to be executed unexpectedly (outside the regular update timeframes) and apply patches in a controlled manner according to the procedure usual for your organization.<\/li>\n          <\/ol>\n          <p>Do you have systems where the risk is high (for example, systems with sensitive or special personal data)? If so, do you have any possible indications that Java is being used with Spring Framework and updates are not yet available? Then consider temporarily disabling the system.<\/p>\n        <\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-4137\" class=\"elementor-tab-title\" data-tab=\"7\" role=\"button\" aria-controls=\"elementor-tab-content-4137\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What should your organization do in case of potential abuse?<\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-4137\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"7\" role=\"region\" aria-labelledby=\"elementor-tab-title-4137\">\n          <p>If your organization is suspected to have been the victim of an attack, the urgent advice is to have research conducted into the cause, to what extent attackers may have compromised other systems and what information may have been accessed unauthorized.<\/p>\n          <ol>\n            <li>If possible, disconnect affected systems from the network, but leave them on (because of possible traces such as volatile memory &#8211; RAM);<\/li>\n            <li>Have the affected systems forensically examined; ensure adequate backups;<\/li>\n            <li>Reset your passwords and user data;<\/li>\n            <li>Report to the Police;<\/li>\n            <li>Consider filing a report with the Personal Data Authority.<\/li>\n          <\/ol>\n          <p>Does your organization currently have an incident? Our Computer Emergency Response Teams (CERT) are available to organizations 24\/7 to support IT Security Incidents.<\/p>\n          <p>Then call<a href=\"tel:+31881330700\"> 088 133 0700<\/a> and we will do our utmost to help you as quickly as possible.<a href=\"https:\/\/www.cyber-security-online.nl\/en\/incident-response-specialist-24-7-availability\/\" data-mil=\"6730\">(Learn more about our Incident Response Service.<\/a>)<\/p>\n        <\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2dfe00a elementor-widget elementor-widget-button\" data-id=\"2dfe00a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/04\/NFIR-Threat-Intelligence-Report-Indicaties-dat-kwetsbaarheid-Spring4Shell-CVE-2022-22965-mogelijk-actief-misbruikt-wordt.pdf\" target=\"_blank\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t<span class=\"elementor-button-icon\">\n\t\t\t\t<i aria-hidden=\"true\" class=\"far fa-file-pdf\"><\/i>\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Download Threat Intelligence Report - Indications that vulnerability Spring4Shell (CVE-2022-22965) may be actively exploited here<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5a098fc elementor-widget elementor-widget-text-editor\" data-id=\"5a098fc\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Is your organization suspected of being the victim of an attack? <a href=\"https:\/\/www.cyber-security-online.nl\/en\/incident-response-specialist-24-7-availability\/\">If so, we urgently advise you to have an investigation carried out into the cause of the<\/a> attack, the extent to which attackers may have compromised other systems and what information may have been accessed without authorisation.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5419f76 elementor-widget elementor-widget-text-editor\" data-id=\"5419f76\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>\n            <em>Disclaimer: NFIR has made every effort to make this information accurate and reliable. However, the information provided is without any guarantee of any kind and its use is entirely at the risk of the user. NFIR assumes no responsibility or liability for the accuracy, content, completeness, legality or reliability of the information provided.<\/em>\n          <\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>In recent days, many organizations have asked for our help in making the right decisions around applications in response to the Spring4Shell vulnerability. More and [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":8763,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"none","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/04\/Spring4Shell_vulnerability_flow_NFIR-NL-1.0.png","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"both","_seopress_redirections_param":"","_seopress_redirections_type":301,"_seopress_analysis_target_kw":"","_seopress_news_disabled":"","_seopress_video_disabled":"","_seopress_video":[],"_seopress_pro_schemas_manual":[],"_seopress_pro_rich_snippets_disable_all":"","_seopress_pro_rich_snippets_disable":[],"_seopress_pro_schemas":[],"site-sidebar-layout":"default","site-content-layout":"default","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"default","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[29,51],"tags":[],"class_list":["post-9120","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-media-en","category-threat-intelligence-en"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/posts\/9120","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/comments?post=9120"}],"version-history":[{"count":0,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/posts\/9120\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/media\/8763"}],"wp:attachment":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/media?parent=9120"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/categories?post=9120"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/tags?post=9120"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}