Skip to main content

Vendor/product archive

redhat / drools CVEs

Beta · best-effort

3 CVEs tagged to redhat / drools1 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2021-41411

Published Jun 16, 2022

drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-8125

Published Apr 21, 2015

XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted BPM…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1