CVE-2022-1415
published 2023-09-11CVE-2022-1415: A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to…
PriorityP354high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.04%
60.2th percentile
A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | >= 4.15.0 < 5.4.220 | 5.4.220 |
| linux | linux_kernel | >= 5.11.0 < 5.15.75 | 5.15.75 |
| linux | linux_kernel | >= 5.16.0 < 5.19.17 | 5.19.17 |
| linux | linux_kernel | >= 5.20.0 < 6.0.3 | 6.0.3 |
| linux | linux_kernel | >= 5.5.0 < 5.10.150 | 5.10.150 |
| redhat | decision_manager | — | — |
| redhat | drools | — | — |
| redhat | process_automation | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
RISC-V: Make port I/O string accessors actually work
osv·2025-12-09
CVE-2022-50647 RISC-V: Make port I/O string accessors actually work
RISC-V: Make port I/O string accessors actually work
In the Linux kernel, the following vulnerability has been resolved:
RISC-V: Make port I/O string accessors actually work
Fix port I/O string accessors such as `insb', `outsb', etc. which use
the physical PCI port I/O address rather than the corresponding memory
mapping to get at the requested location, which in turn breaks at least
accesses made by our parport driver to a PCIe parallel port such as:
PCI parallel port detected: 1415:c118, I/O at 0x1000(0x1008), IRQ 20
parport0: PC-style at 0x1000 (0x1008), irq 20, using FIFO [PCSPP,TRISTATE,COMPAT,EPP,ECP]
causing a memory access fault:
Unable to handle kernel access to user memory without uaccess routines at virtual address 0000000000001008
Oops [#1]
Modules linked in:
CPU: 1 PID:
GHSA
Drools Core Deserialization of Untrusted Data vulnerability
ghsa·2023-09-11
CVE-2022-1415 [MEDIUM] CWE-502 Drools Core Deserialization of Untrusted Data vulnerability
Drools Core Deserialization of Untrusted Data vulnerability
A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.
OSV
Drools Core Deserialization of Untrusted Data vulnerability
osv·2023-09-11
CVE-2022-1415 [MEDIUM] Drools Core Deserialization of Untrusted Data vulnerability
Drools Core Deserialization of Untrusted Data vulnerability
A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.
Red Hat
drools: unsafe data deserialization in StreamUtils
vendor_redhat·2022-10-28·CVSS 8.1
CVE-2022-1415 [HIGH] CWE-502 drools: unsafe data deserialization in StreamUtils
drools: unsafe data deserialization in StreamUtils
A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.
A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.
Package: drools-core (Red Hat build of Apache Camel for Spring Boot 3) - Not affected
Package: drools-core (Red Hat build of Quarkus) - Not affected
Package: drools-core (Red Hat Decision Manager 7) - Affected
P
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2022:6813https://access.redhat.com/security/cve/CVE-2022-1415https://bugzilla.redhat.com/show_bug.cgi?id=2065505https://access.redhat.com/errata/RHSA-2022:6813https://access.redhat.com/security/cve/CVE-2022-1415https://bugzilla.redhat.com/show_bug.cgi?id=2065505
2023-09-11
Published