Server-Side Request Forgery (SSRF) in Spring Framework - CVE-2024-22259

 

Server-Side Request Forgery (SSRF) in Spring Framework - CVE-2024-22259

Published: March 19, 2024 / Updated: November 20, 2025


Vulnerability identifier: #VU87614
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2024-22259
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input when parsing URL with the UriComponentsBuilder component. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.

Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.


Affected software

Spring Framework
UrbanCode Build
DB2 Data Management Console
OpenPages for IBM Cloud Pak for Data
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
OpenPages Cloud pak for data service version
IBM Engineering Requirements Management DOORS Next
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
IBM Planning Analytics Workspace
Storage Copy Data Management
Cloud Pak for Network Automation
Oxygen Feedback
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
Dell Policy Manager for Secure Connect Gateway (SCG)
DevOps
MobileFirst Platform
Maximo Application Suite - Monitor Component
Dell Data Protection Central
Confluence Server
Confluence Data Center
Enterprise Project Connection
Crowd Data Center
Bitbucket Data Center
Bamboo Server
Unified OSS Console Assurance Monitoring (UOCAM)
IBM Cloud Object Storage Systems
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Dell Secure Connect Gateway
IBM SPSS Collaboration and Deployment Services
IBM Security Verify Governance
IBM Cloud Pak for Business Automation
IBM Automation Decision Services
IBM Observability with Instana
watsonx.data
Crowd Server
IBM Tivoli Application Dependency Discovery Manager
Juniper Secure Analytics (JSA)
QRadar Suite
Bitbucket Server
AMQ Broker
Identity Manager
Oracle Communications Cloud Native Core Console
Library Support for Spring
IBM Qradar SIEM
IBM Cognos Controller

How to mitigate CVE-2024-22259

Install updates from vendor's website.

Spring Framework - addressed in versions 5.3.33, 6.0.18, 6.1.5
Confluence Server - addressed in versions 7.19.23, 8.5.9, 8.9.1
Confluence Data Center - addressed in versions 7.19.23, 8.5.9, 8.9.1
watsonx.data - update to 2.1
DB2 Data Management Console - update to 3.1.13
OpenPages for IBM Cloud Pak for Data - update to 5.3.0
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2
Crowd Data Center - addressed in versions 5.1.11, 5.2.6, 5.3.3, 6.0.1
Crowd Server - addressed in versions 5.1.11, 5.2.6, 5.3.3, 6.0.1
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
Bitbucket Data Center - addressed in versions 8.9.14, 8.19.3
Bitbucket Server - addressed in versions 8.9.14, 8.19.3
Bamboo Server - addressed in versions 9.2.13, 9.5.3, 9.6.1
OpenPages Cloud pak for data service version - update to 9.6.0
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
QRadar Suite - update to 1.10.22.0
IBM Planning Analytics Workspace - addressed in versions 2.0.95, 2.1.2
Storage Copy Data Management - update to 2.2.26.0
Cloud Pak for Network Automation - update to 2.7.5
Library Support for Spring - update to 2.7.29
Unified OSS Console Assurance Monitoring (UOCAM) - update to 3.1.4
IBM Cloud Object Storage Systems - addressed in versions 3.18.0.50, 3.18.2.45
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.0
Oxygen Feedback - update to 5.0 2024090417
watsonx Assistant Cartridge - update to 5.1.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.1
Dell Secure Connect Gateway - update to 5.24.00.14
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.24.00.14
DevOps - update to 7.0.0.2
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF03
AMQ Broker - update to 7.12.0
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202404220901
IBM SPSS Collaboration and Deployment Services - update to 8.5.0.0.13
Maximo Application Suite - Monitor Component - addressed in versions 8.10.9, 8.11.6
IBM Security Verify Governance - update to 10.0.2.0.3
IBM Cognos Controller - addressed in versions 11.0.1.4, 11.1.0.2
Dell Data Protection Central - update to 19.11.0-2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF035, 21.0.3.32, 23.0.2.4, 24.0.0-IF001
IBM Automation Decision Services - update to 23.0.2.0.4
IBM Observability with Instana - update to 271

External References

Related Security Bulletins