The serialization implementation in JBoss Drools in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 and JBoss Enterprise SOA Platform 4.2 and 4.3 supports the embedding of class files, which allows remote attackers to execute arbitrary code via a crafted static initializer.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5038 | The serialization implementation in JBoss Drools in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 and JBoss Enterprise SOA Platform 4.2 and 4.3 supports the embedding of class files, which allows remote attackers to execute arbitrary code via a crafted static initializer. |
Github GHSA |
GHSA-qvq6-cw53-rmwg | Drools Improper Input Validation vulnerability allows remote attackers to execute arbitrary code in JBoss EAP |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T03:18:53.023Z
Reserved: 2010-10-01T00:00:00Z
Link: CVE-2010-3708
No data.
Status : Deferred
Published: 2010-12-30T21:00:01.267
Modified: 2025-04-11T00:51:21.963
Link: CVE-2010-3708
OpenCVE Enrichment
No data.
EUVD
Github GHSA