Tungsten Automation Knowledge

Tungsten Automation products and Spring4Shell vulnerability information CVE-2022-22965

000019228 · Troubleshooting · Last Updated: Sep 10, 2026

Tungsten Automation is aware of the recently disclosed Spring4Shell vulnerabilities (CVE-2022-22965) in the Spring Core Framework of the Spring Core on Java Development Kit (JDK) version 9 or later. The following products are using the potentially vulnerable version.  is in the process of evaluating the usage of Spring4Shell in the products below and will create patches wherever it is needed, as a priority.

Products not listed on this page have been evaluated and are not vulnerable.
 
Affected ProductsRemediation Status Community Product Discussion URL
Bookmark your product's post for any future updates
Communication Manager (KCM) KCM is not vulnerable to the Spring4Shell zero-day vulnerability (CVE-2022-22965). KCM does use Spring parameter binding, but to a native (String) type. It does not bind to a POJO. Communications Manager Release Announcements
Device Web Service (DWS)The Java Development Kit (JDK) included is below JDK9 and is therefore not impacted. ControlSuite Release Announcements
Invoice PortalInvoice Portal does not use Java Development Kit version 9 (JDK9) or later and therefore is not impacted.
Please refer to the Does the spring4shell vulnerability CVE-2022-22965 affect Invoice Portal article for details.
ReadSoft Release Announcements
RPAPatches are available
See Is RPA impacted by the CVE-2022-22965 RCE Vulnerability article.
Robotic Process Automation Release Announcements
MarkViewMarkView does not use Java Development Kit version 9 (JDK9) or later and therefore is not impacted.
Please refer to the Does the spring4shell vulnerability CVE-2022-22965 affect MarkView article for details.
MarkView Release Announcements
PrintixPrintix is not vulnerable as Spring Core is not deployed as WAR. 
SafeComThe Java Development Kit (JDK) included is below JDK9 and is therefore not impacted. 
Tungsten SignDocPotentially vulnerable. R&D is evaluating if Tungsten SignDoc is impacted by this vulnerability.
Please refer to the Spring4shell vulnerability in Tungsten SignDoc article for more information.
Tungsten SignDoc Release Announcements

Applies to

ProductVersionBuildEnvironmentHardware
General Support

Sections recovered from body HTML: none detected.

https://aio-eus-uat-cae-aif-app14-local.redglacier-35d7ee4f.eastus.azurecontainerapps.io/article/19228 | Article 000019228 | Printed Sep 30, 2026

Back to the article · use your browser's Print command, or save the PDF.