VDB
CVE-2022-1415
CVE-2022-1415
PUBLISHED
CVSS 8.1 HIGH
Reported by redhat · Published September 11, 2023
A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.
Risk Scores
CVSS 3.1
8.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | RHPAM 7.13.1 async | |
| Red Hat | Red Hat build of Apache Camel for Spring Boot | |
| Red Hat | Red Hat build of Quarkus | |
| Red Hat | Red Hat Decision Manager 7 | |
| Red Hat | Red Hat Integration Camel K | |
| Red Hat | Red Hat Integration Camel Quarkus | |
| Red Hat | Red Hat JBoss Data Grid 7 | |
| Red Hat | Red Hat JBoss Data Virtualization 6 | |
| Red Hat | Red Hat JBoss Enterprise Application Platform 6 | |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | |
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | |
| Red Hat | Red Hat JBoss Fuse 6 | |
| Red Hat | Red Hat JBoss Fuse 7 | |
| Red Hat | Red Hat JBoss Fuse Service Works 6 | |
| Red Hat | Red Hat Process Automation 7 | |
| Red Hat | Red Hat build of Quarkus | |
| Maven | org.drools:drools-core | 0, 0, 0 |
| Red Hat | Red Hat JBoss Data Grid 7 | |
| Red Hat | Red Hat JBoss Data Virtualization 6 | |
| Red Hat | Red Hat Process Automation 7 |
…and 12 more
Timeline
- Feb 10, 2023 CVE Published
- Sep 12, 2023 EPSS Score
- Oct 15, 2023 EPSS Score
- Nov 16, 2023 EPSS Score
- Jan 20, 2024 EPSS Score
- Feb 22, 2024 EPSS Score
- Mar 26, 2024 EPSS Score
- Apr 27, 2024 EPSS Score
- May 30, 2024 EPSS Score
- Jul 1, 2024 EPSS Score
- Sep 4, 2024 EPSS Score
- Sep 25, 2024 CVE Updated
References
- RHSA-2022:6813 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2065505 issue-trackingx_refsource_REDHAT
- https://github.com/advisories/GHSA-m5q8-58wh-xxq4 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-1415 advisory