VDB

CVE-2022-1415

CVE-2022-1415 PUBLISHED CVSS 8.1 HIGH

Reported by redhat · Published September 11, 2023

A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.

Risk Scores

CVSS 3.1
8.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
Red HatRHPAM 7.13.1 async
Red HatRed Hat build of Apache Camel for Spring Boot
Red HatRed Hat build of Quarkus
Red HatRed Hat Decision Manager 7
Red HatRed Hat Integration Camel K
Red HatRed Hat Integration Camel Quarkus
Red HatRed Hat JBoss Data Grid 7
Red HatRed Hat JBoss Data Virtualization 6
Red HatRed Hat JBoss Enterprise Application Platform 6
Red HatRed Hat JBoss Enterprise Application Platform 7
Red HatRed Hat JBoss Enterprise Application Platform Expansion Pack
Red HatRed Hat JBoss Fuse 6
Red HatRed Hat JBoss Fuse 7
Red HatRed Hat JBoss Fuse Service Works 6
Red HatRed Hat Process Automation 7
Red HatRed Hat build of Quarkus
Mavenorg.drools:drools-core0, 0, 0
Red HatRed Hat JBoss Data Grid 7
Red HatRed Hat JBoss Data Virtualization 6
Red HatRed Hat Process Automation 7

…and 12 more

Timeline

  • Feb 10, 2023 CVE Published
  • Sep 12, 2023 EPSS Score
  • Oct 15, 2023 EPSS Score
  • Nov 16, 2023 EPSS Score
  • Jan 20, 2024 EPSS Score
  • Feb 22, 2024 EPSS Score
  • Mar 26, 2024 EPSS Score
  • Apr 27, 2024 EPSS Score
  • May 30, 2024 EPSS Score
  • Jul 1, 2024 EPSS Score
  • Sep 4, 2024 EPSS Score
  • Sep 25, 2024 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›