CVE-2022-1415
Drools: unsafe data deserialization in streamutils
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.1EPSS 1.0%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
11 sep 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Productos afectados
Red Hat · Red Hat build of Apache Camel for Spring BootRed Hat · Red Hat build of QuarkusRed Hat · Red Hat Decision Manager 7Red Hat · Red Hat Integration Camel KRed Hat · Red Hat Integration Camel QuarkusRed Hat · Red Hat JBoss Data Grid 7Red Hat · Red Hat JBoss Data Virtualization 6Red Hat · Red Hat JBoss Enterprise Application Platform 6Red Hat · Red Hat JBoss Enterprise Application Platform 7Red Hat · Red Hat JBoss Enterprise Application Platform Expansion PackRed Hat · Red Hat JBoss Fuse 6Red Hat · Red Hat JBoss Fuse 7Red Hat · Red Hat JBoss Fuse Service Works 6Red Hat · Red Hat Process Automation 7Red Hat · RHPAM 7.13.1 async¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →