FOI 21/22-1376 - Spring4Shell Cybersecurity Vulnerability & Risk
Scope
-
Please provide a copy of the NDIA’s Spring4Shell cybersecurity threat and vulnerability assessment.
-
Does the NDIA have any products, services or systems using the Spring Framework (Java)?
-
Has the NDIA or the NDIA’s data been impacted in anyway by the Spring4Shell vulnerability? This includes all vendor/3rd party products and services such as VMWare, Microsoft Azure or other recently impacted systems and warnings.
Response
-
No formal threat or vulnerability assessment was produced, as this was handled as part of normal operational capability. NDIA’s vulnerability management process considers likelihood and consequence of vulnerabilities related to NDIA systems as well as mitigating controls applied.
-
Yes, however the Agency does not run specific known-vulnerable configurations on any of its products, services or systems that use the Spring Framework (Java).
-
NDIA systems or data have not been impacted as a result of the Spring4Shell vulnerability.