First published: Thu Jan 09 2014(Updated: )
A code execution vulnerability has been discovered in Drools. The flaw allows remote authenticated attackers to submit arbitrary Java code in MVEL or Drools expressions, the code would be executed within the security context of the application server.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Jboss Bpm Suite | =6.0.0 | |
Redhat Jboss Drools | ||
Redhat Jboss Enterprise Brms Platform | =6.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.