Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.
A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.
Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.
Each line is one product that two or more sources describe differently. Same identifier means they both named it the same way; linked identifier means they named it differently and meet at a package URL or CPE both assert. This is recorded rather than resolved: a vendor saying "not affected" where an ecosystem says "affected" is a fact about the disclosure, and flattening it would hide the more useful half.
| Product | Status | Versions | Remediation | Source | |
|---|---|---|---|---|---|
| red_hat_virtualization_4:rhvm-dependencies.src rhvm-dependencies.src as a component of Red Hat Virtualization 4 | affected | no version stated vendor label: rhvm-dependencies.src | workaround fix in another branch | csaf_redhat | |
| red_hat_integration_camel_quarkus_1:spring-beans spring-beans as a component of Red Hat Integration Camel Quarkus 1 | affected | no version stated vendor label: spring-beans | workaround fix in another branch | csaf_redhat | |
| red_hat_jboss_a-mq_6:spring-webmvc spring-webmvc as a component of Red Hat JBoss A-MQ 6 | affected | no version stated vendor label: spring-webmvc | workaround fix in another branch | csaf_redhat | |
| red_hat_jboss_fuse_6:spring-webmvc spring-webmvc as a component of Red Hat JBoss Fuse 6 | affected | no version stated vendor label: spring-webmvc | workaround fix in another branch | csaf_redhat | |
| CEQ 2.2.1-1 (CVE-2022-22965) | fixed | no version stated | vendor fix | csaf_redhat | |
| Red Hat AMQ 7.8.6 | fixed | no version stated | vendor fix | csaf_redhat | |
| Red Hat AMQ 7.9.4 | fixed | no version stated | vendor fix | csaf_redhat | |
| Red Hat Fuse 7.10.2 | fixed | no version stated | vendor fix | csaf_redhat | |
| RHDM 7.12.1 async | fixed | no version stated | vendor fix | csaf_redhat | |
| RHINT Camel-K 1.6.5 | fixed | no version stated | vendor fix | csaf_redhat | |
| RHPAM 7.12.1 async | fixed | no version stated | vendor fix | csaf_redhat | |
| https://github.com/spring-projects/spring-framework | affected | < cfa701b8726f06528e9d408b1b94f333f70da45f | vendor fix → cfa701b8726f06528e9d408b1b94f333f70da45f | osv | |
| https://github.com/spring-projects/spring-framework | affected | >= 5acffaa72da10ba42fe547eeea44d8615cbf99b9, < 707a24c48b21fc35e8be715afc80f020a24a9714 | vendor fix → 707a24c48b21fc35e8be715afc80f020a24a9714 | osv | |
| org.springframework:spring-beans | affected | < 5.2.20.RELEASE | vendor fix → 5.2.20.RELEASE | osv GHSA-36p3-wjmg-h94x | |
| org.springframework:spring-beans | affected | >= 5.3.0, < 5.3.18 | vendor fix → 5.3.18 | osv GHSA-36p3-wjmg-h94x | |
| org.springframework:spring-webflux | affected | < 5.2.20.RELEASE | vendor fix → 5.2.20.RELEASE | osv GHSA-36p3-wjmg-h94x | |
| org.springframework:spring-webflux | affected | >= 5.3.0, < 5.3.18 | vendor fix → 5.3.18 | osv GHSA-36p3-wjmg-h94x | |
| org.springframework:spring-webmvc | affected | < 5.2.20.RELEASE | vendor fix → 5.2.20.RELEASE | osv GHSA-36p3-wjmg-h94x | |
| org.springframework:spring-webmvc | affected | >= 5.3.0, < 5.3.18 | vendor fix → 5.3.18 | osv GHSA-36p3-wjmg-h94x | |
| org.springframework.boot:spring-boot-starter-web | affected | < 2.5.12 | vendor fix → 2.5.12 | osv GHSA-36p3-wjmg-h94x | |
| org.springframework.boot:spring-boot-starter-web | affected | >= 2.6.0, < 2.6.6 | vendor fix → 2.6.6 | osv GHSA-36p3-wjmg-h94x | |
| org.springframework.boot:spring-boot-starter-webflux | affected | < 2.5.12 | vendor fix → 2.5.12 | osv GHSA-36p3-wjmg-h94x | |
| org.springframework.boot:spring-boot-starter-webflux | affected | >= 2.6.0, < 2.6.6 | vendor fix → 2.6.6 | osv GHSA-36p3-wjmg-h94x | |
| https://github.com/spring-projects/spring-framework | fixed | cfa701b8726f06528e9d408b1b94f333f70da45f | vendor fix → cfa701b8726f06528e9d408b1b94f333f70da45f | osv | |
| https://github.com/spring-projects/spring-framework | fixed | 707a24c48b21fc35e8be715afc80f020a24a9714 | vendor fix → 707a24c48b21fc35e8be715afc80f020a24a9714 | osv | |
| org.springframework:spring-beans | fixed | 5.2.20.RELEASE | vendor fix → 5.2.20.RELEASE | osv GHSA-36p3-wjmg-h94x | |
| org.springframework:spring-beans | fixed | 5.3.18 | vendor fix → 5.3.18 | osv GHSA-36p3-wjmg-h94x | |
| org.springframework:spring-webflux | fixed | 5.2.20.RELEASE | vendor fix → 5.2.20.RELEASE | osv GHSA-36p3-wjmg-h94x | |
| org.springframework:spring-webflux | fixed | 5.3.18 | vendor fix → 5.3.18 | osv GHSA-36p3-wjmg-h94x | |
| org.springframework:spring-webmvc | fixed | 5.2.20.RELEASE | vendor fix → 5.2.20.RELEASE | osv GHSA-36p3-wjmg-h94x | |
| org.springframework:spring-webmvc | fixed | 5.3.18 | vendor fix → 5.3.18 | osv GHSA-36p3-wjmg-h94x | |
| org.springframework.boot:spring-boot-starter-web | fixed | 2.5.12 | vendor fix → 2.5.12 | osv GHSA-36p3-wjmg-h94x | |
| org.springframework.boot:spring-boot-starter-web | fixed | 2.6.6 | vendor fix → 2.6.6 | osv GHSA-36p3-wjmg-h94x | |
| org.springframework.boot:spring-boot-starter-webflux | fixed | 2.5.12 | vendor fix → 2.5.12 | osv GHSA-36p3-wjmg-h94x | |
| org.springframework.boot:spring-boot-starter-webflux | fixed | 2.6.6 | vendor fix → 2.6.6 | osv GHSA-36p3-wjmg-h94x | |
| n/a/Spring Framework n/a · Spring Framework | affected | Spring Framework versions 5.3.X prior to 5.3.18+, 5.2.x prior to 5.2.20+ and all old and unsupported versions | none available | cve_cna |
A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.