CVE-2022-1415 - CVE House
Back to Database
Status published High CVE-2022-1415

Drools: unsafe data deserialization in streamutils

Vulnerability Description

A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-1415

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Red Hat would like to thank Paulino Calderon (Websec) for reporting this issue.

Affected Vendor

Affected Software

RHPAM 7.13.1 async, Red Hat build of Apache Camel for Spring Boot, Red Hat build of Quarkus, Red Hat Decision Manager 7, Red Hat Integration Camel K, Red Hat Integration Camel Quarkus, Red Hat JBoss Data Grid 7, Red Hat JBoss Data Virtualization 6, Red Hat JBoss Enterprise Application Platform 6, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat JBoss Fuse 6, Red Hat JBoss Fuse 7, Red Hat JBoss Fuse Service Works 6, Red Hat Process Automation 7
Vulnerable Versions:
Unknown

Timeline

Official Publish: September 11th, 2023
Last Modified: September 25th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Weaknesses (CWE)