CVE-2022-1415: Drools: unsafe data deserialization in streamutils
A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.
Other sources
It was found that some utility classes in Drools core did not use proper safeguards when deserializing data. An authed attacker could construct malicious serialized objects (usually called gadgets) and use this flaw to achieve code execution on the server.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-1415?
CVE-2022-1415 is a vulnerability in Drools core that allows an authenticated attacker to construct malicious serialized objects and achieve code execution on the server.
How severe is CVE-2022-1415?
CVE-2022-1415 has a severity rating of 8.8 (high).
Which software versions are affected by CVE-2022-1415?
CVE-2022-1415 affects Redhat Decision Manager 7.0, Redhat Drools 7.69.0, Redhat Process Automation 7.0, and org.drools:drools-core up to version 7.69.0.Final.
How can an attacker exploit CVE-2022-1415?
CVE-2022-1415 allows an authenticated attacker to exploit the vulnerability by constructing and sending malicious serialized objects (gadgets) to the server.
Where can I find more information about CVE-2022-1415?
You can find more information about CVE-2022-1415 at the following references: [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2022:6813) and [CVE-2022-1415 on Red Hat's Security Page](https://access.redhat.com/security/cve/CVE-2022-1415).