Drools
This hub aggregates every CVE we track for Drools, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Operating Systemson-prem
3
CVEs tracked
1
Critical
2
High
0
In CISA KEV
Severity distribution
HIGH2CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 3 most recently published vulnerabilities affecting Drools.
- CVE-2022-1415Drools: unsafe data deserialization in streamutils8.1
- CVE-2021-41411drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.9.8
- CVE-2014-8125XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted BPMN2 file.7.5
Product normalization is registry-driven with AI assist and human review. How it works