<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T06:46:05.362250+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2022-1415</id>
    <title>CVE-2022-1415 — Drools: unsafe data deserialization in streamutils</title>
    <updated>2026-10-06T06:46:05.381474+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Red Hat RHPAM 7.13.1 async, Red Hat build of Apache Camel for Spring Boot, Red Hat build of Quarkus, Red Hat Decision Manager 7, Red Hat Integration Camel K, Red Hat Integration Camel Quarkus, Red Hat JBoss Data Grid 7, Red Hat JBoss Data Virtualization 6, Red Hat JBoss Enterprise Application Platform 6, Red Hat JBoss Enterprise Application Platform 7 and 5 more</p>
<p>A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2022-1415"/>
  </entry>
</feed>
