CVE-2022-1415 Vulnerability Details

  /     /     /  

CVE-2022-1415 Metadata Quick Info

CVE Published: 11/09/2023 | CVE Updated: 25/09/2024 | CVE Year: 2022
Source: redhat | Vendor: Red Hat | Product: RHPAM 7.13.1 async
Status : PUBLISHED

CVE-2022-1415 Description

A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-502
CWE Name: Deserialization of Untrusted Data
Source: Red Hat

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).