Zero-day “Spring4Shell”

Since this week there is a new zero-day vulnerability in the Spring framework. Please note that we are aware of this and currently analyzing how far the PTV xServer is affected.
 
 
We like to share the current state of our analysis with you.
The essential requirement for exploiting the vulnerability is a JDK9. We are still running JDK8 on all PTV xServer API versions.
Thus, the PTV xServer is not affected by CVE-2022-22965 (according to the current status).
 
Of course, there may be new findings, so we will continue to investigate this issue. We will inform you as soon as there are further findings. To stay tuned subscribe to our blog.
 
 
 

By Isabel Honikel

Senior Technical Product Manager