<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 10:51:53 +0000</lastBuildDate>
    <item>
      <title>CVE-2022-1415 — Drools: unsafe data deserialization in streamutils</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2022-1415</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Red Hat RHPAM 7.13.1 async, Red Hat build of Apache Camel for Spring Boot, Red Hat build of Quarkus, Red Hat Decision Manager 7, Red Hat Integration Camel K, Red Hat Integration Camel Quarkus, Red Hat JBoss Data Grid 7, Red Hat JBoss Data Virtualization 6, Red Hat JBoss Enterprise Application Platform 6, Red Hat JBoss Enterprise Application Platform 7 and 5 more&lt;/p&gt;
&lt;p&gt;A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Red Hat RHPAM 7.13.1 async, Red Hat build of Apache Camel for Spring Boot, Red Hat build of Quarkus, Red Hat Decision Manager 7, Red Hat Integration Camel K, Red Hat Integration Camel Quarkus, Red Hat JBoss Data Grid 7, Red Hat JBoss Data Virtualization 6, Red Hat JBoss Enterprise Application Platform 6, Red Hat JBoss Enterprise Application Platform 7 and 5 more&lt;/p&gt;
&lt;p&gt;A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2022-1415</guid>
    </item>
  </channel>
</rss>
