First published: Tue Sep 14 2010(Updated: )
The drools serialization format allows to embed class files. Upon deserialization those are loaded by the VM that runs the drools engine. If that (attacker-controlled) class files defines code in a static initializer it is executed during deserialization.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat JBoss Enterprise Application Platform | =4.3.0 | |
Red Hat JBoss Enterprise Application Platform | =4.3.0-cp01 | |
Red Hat JBoss Enterprise Application Platform | =4.3.0-cp02 | |
Red Hat JBoss Enterprise Application Platform | =4.3.0-cp03 | |
Red Hat JBoss Enterprise Application Platform | =4.3.0-cp04 | |
Red Hat JBoss Enterprise Application Platform | =4.3.0-cp05 | |
Red Hat JBoss Enterprise Application Platform | =4.3.0-cp06 | |
Red Hat JBoss Enterprise Application Platform | =4.3.0-cp07 | |
Red Hat JBoss Enterprise Application Platform | =4.3.0-cp08 | |
Redhat Jboss Enterprise Soa Platform | =4.2.0 | |
Redhat Jboss Enterprise Soa Platform | =4.2.0-cp01 | |
Redhat Jboss Enterprise Soa Platform | =4.2.0-cp02 | |
Redhat Jboss Enterprise Soa Platform | =4.2.0-cp03 | |
Redhat Jboss Enterprise Soa Platform | =4.2.0-cp04 | |
Redhat Jboss Enterprise Soa Platform | =4.2.0-cp05 | |
Redhat Jboss Enterprise Soa Platform | =4.2.0-tp02 | |
Redhat Jboss Enterprise Soa Platform | =4.3.0 | |
Redhat Jboss Enterprise Soa Platform | =4.3.0-cp01 | |
Redhat Jboss Enterprise Soa Platform | =4.3.0-cp02 | |
Redhat Jboss Enterprise Soa Platform | =4.3.0-cp03 | |
Redhat Jboss Enterprise Soa Platform | =4.3.0-cp04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.