VendorsRed Hatdroolsall versions
Vulnerabilities

Red Hat RedHat Drools

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2021-41411
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.
Published 2022-06-16 · Modified
9.8EPSS 0.013
CVE-2022-1415
Drools: unsafe data deserialization in streamutils
Published 2023-09-11 · Modified
8.8EPSS 0.010
CVE-2014-8125
XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted BPMN2 file.
Published 2015-04-21 · Modified
7.5EPSS 0.026