Teamcenter Enterprise Security vulnerability "SpringShell" (CVE-2022-22965)

2022-08-02T14:18:50Z
Enterprise Knowledge Foundation

Summary


Details

A recent security vulnerability "SpringShell" was announced for the Spring Framework or derivate frameworks and published as CVE-2022-22965 (please, review https://www.microsoft.com/security/blog/2022/04/04/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965/).

The customer would need to know if the thin client versions of TeamCenter Enterprise versions 8.1 MP01 and 9.0 MP03 could be vulnerable. Would cfgedit2.exe be a vulnerable?

Solution

Our Development team has investigated this, and deduced that TcEnterprise does not use any Spring software.   So this vulnerability should not affect TcEnterprise.

Notes

KB Article ID# PL8635314

Contents

SummaryDetails

Associated Components

OMF Server & Clients