Spring4Shell (CVE-2022-22965)

Summary

ReadiNow does not have direct exposure to this vulnerability.

Background

In March 2022, a Spring application running on JDK 9+ was found to have a vulnerability known as the Spring4Shell (CVE- 2022-22965)

ReadiNow Response 

ReadiNow promptly reviewed all code and environments. The ReadiNow platform itself does not use Spring nor Apache and so is not vulnerable to CVE-2022-22965. We are continuing to review any 3rd party vendors and software to see if they are at risk and will promptly apply any patches if required

Update

This bulletin was last updated on 05 April 2022.

New information will be posted here if required