Description
JBoss Drools, Red Hat JBoss BRMS before 6.0.1, and Red Hat JBoss BPM Suite before 6.0.1 allows remote authenticated users to execute arbitrary Java code via a (1) MVFLEX Expression Language (MVEL) or (2) Drools expression.
Remediation
References
http://rhn.redhat.com/errata/RHSA-2014-0371.html
http://rhn.redhat.com/errata/RHSA-2014-0372.html
http://secunia.com/advisories/57716
http://secunia.com/advisories/57719
Related Vulnerabilities
CVE-2022-25883 Vulnerability in npm package semver
CVE-2020-1937 Vulnerability in maven package org.apache.kylin:kylin-server-base
CVE-2022-34798 Vulnerability in maven package org.jenkins-ci.plugins:ec2-deployment-dashboard
CVE-2014-3464 Vulnerability in maven package org.wildfly:wildfly-ejb3
CVE-2023-29526 Vulnerability in maven package org.xwiki.platform:xwiki-platform-rendering-async-api