Back

HIGH

JBoss drools deserialization remote code execution

Published Dec 30, 2010

Description

The serialization implementation in JBoss Drools in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 and JBoss Enterprise SOA Platform 4.2 and 4.3 supports the embedding of class files, which allows remote attackers to execute arbitrary code via a crafted static initializer.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 30, 2010
Updated Aug 7, 2024
Reserved Oct 1, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Dec 1, 2010
GHSA-QVQ6-CW53-RMWG