---
title: Spring4Shell Security Issue | Ascertia | Blog
description: Ascertia is delighted to share its products are unaffected by the recent Spring4Shell security issue. Read more about this latest cybersecurity news.
---

[![](https://blog.ascertia.com/hubfs/asc-blog-logo-detail.png)](https://blog.ascertia.com/)

##### [View all posts](https://blog.ascertia.com/)

[Contact Us](https://www.ascertia.com/company/contact-us/)

# Ascertia's response to Spring4Shell security issue

Posted by [Sven Prinsloo](https://blog.ascertia.com/author/sven-prinsloo) on Apr 6, 2022 12:02:26 PM

![](https://blog.ascertia.com/hubfs/Sven%20Prinsloo.png)

In this blog, we discuss the recent Spring4Shell security issue - and Ascertia's response to it.

## What is the Spring Framework?

[Spring Framework](https://spring.io/projects/spring-framework) provides a comprehensive programming and configuration model for modern Java-based enterprise applications - on any kind of deployment platform.

## **Spring4Shell security issue summary**

Ascertia has become aware of a security issue within the Spring Framework which could be exploited by an attacker. No currently released Ascertia products make use of the Spring Framework for any data binding operations. 

### Spring4Shell (SpringShell) issues

- CVE-2022-22965: A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.

Further details are available at: [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22965](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22965) 

## Applicability to Ascertia products

No currently released Ascertia products make use of the Spring Framework for any data binding operations. [ADSS Server](https://www.ascertia.com/products/adss-signing-server/) does include Spring libraries within its file structure, these are used internally to the application.

To ensure that our applications were safe from this exploit, Ascertia has performed the relevant tests on all currently supported versions of ADSS Server, using third party vulnerability assessment tools. The results from these tests indicated that **none** of our products were vulnerable to this CVE.

## Continued investigation and support

Ascertia will continue to monitor this CVE and any related CVEs hereafter and ensure that all remediation is taken to safeguard Ascertia products and customers.

If you have any security-related questions, please contact [Ascertia support](mailto:support@ascertia.com) or your account team.

[Visit Ascertia.com](https://www.ascertia.com/)

This is a search field with an auto-suggest feature attached.

 Search

- There are no suggestions because the search field is empty.

### Recent Posts

### Posts by Topic

- [News (64)](https://blog.ascertia.com/tag/news)
- [Digital Trust (51)](https://blog.ascertia.com/tag/digital-trust)
- [Esignatures & Digital Signatures (41)](https://blog.ascertia.com/tag/esignatures-digital-signatures)
- [Esignatures, Digital Signatures & Digital Signing (25)](https://blog.ascertia.com/tag/esignatures-digital-signatures-digital-signing)
- [Remote Signing (21)](https://blog.ascertia.com/tag/remote-signing)
- [Ascertia Partners (16)](https://blog.ascertia.com/tag/ascertia-partners)
- [Business Process & Workflow Efficiencies (15)](https://blog.ascertia.com/tag/business-process-workflow-efficiencies)

### Subscribe to Blog

### Download this essential eBook

Choosing the right type of e-signature  
for your business

[![Download your eBook](https://no-cache.hubspot.com/cta/default/2937299/065619c2-b2d6-4c65-9820-92c7e0dceaa8.png)](https://cta-redirect.hubspot.com/cta/redirect/2937299/065619c2-b2d6-4c65-9820-92c7e0dceaa8)

- Signing
- EU eIDAS Compliant Advanced & Qualified Signatures
- [SigningHub](https://www.ascertia.com/products/signinghub/)
- [ADSS Signing Server](https://www.ascertia.com/products/adss-signing-server/)

- PKI
- Modular solution for your Trust Service needs
- [ADSS Certificate Authority](https://www.ascertia.com/products/adss-ca-pki-server/)
- [ADSS Registration Authority](https://www.ascertia.com/products/adss-ra-server/)
- [ADSS Validation Authority](https://www.ascertia.com/products/adss-ocsp-server/)
- [ADSS Time Stamp Authority](https://www.ascertia.com/products/adss-tsa-server/)
- [ADSS Archive Authority](https://www.ascertia.com/products/adss-ltans-evidence-server/)

- Tools
- Integrate, test & monitor your Trust Services
- [ADSS Auto File Processor](https://www.ascertia.com/products/adss-auto-file-processor/)
- [ADSS Client SDK](https://www.ascertia.com/products/adss-client-sdk/)

- Solutions
- [Mobile Signatures](https://www.ascertia.com/solutions-by-technology/mobile-signing/)
- [Remote (Cloud) Signing](https://www.ascertia.com/solutions-by-technology/remote-signing/)
- <https://www.linkedin.com/company/ascertia> <https://www.youtube.com/user/ESIGNwithAscertia>

[Terms of Use](https://www.ascertia.com/terms-of-use/)   |   [Privacy Policy](https://www.ascertia.com/company/privacy-policy/)   |   © Ascertia. All rights reserved. ISO 9001:2015 Certified