Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10086

Опубликовано: 15 авг. 2019
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

A flaw was found in the Apache Commons BeanUtils, where the class property in PropertyUtilsBean is not suppressed by default. This flaw allows an attacker to access the classloader.

Меры по смягчению последствий

There is no currently known mitigation for this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7commons-beanutilsAffected
Red Hat BPM Suite 6commons-beanutilsOut of support scope
Red Hat CodeReady Studio 12commons-beanutilsNot affected
Red Hat Enterprise Linux 5jakarta-commons-beanutilsOut of support scope
Red Hat Enterprise Linux 6jakarta-commons-beanutilsOut of support scope
Red Hat JBoss A-MQ 6commons-beanutilsAffected
Red Hat JBoss BRMS 5commons-beanutilsOut of support scope
Red Hat JBoss Data Virtualization 6commons-binutilsOut of support scope
Red Hat JBoss Enterprise Application Platform 5commons-beanutilsOut of support scope
Red Hat JBoss Enterprise Application Platform 6commons-beanutilsOut of support scope

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=1767483apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default

EPSS

Процентиль: 54%
0.00317
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
почти 6 лет назад

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVSS3: 7.3
nvd
почти 6 лет назад

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVSS3: 7.3
debian
почти 6 лет назад

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class wa ...

suse-cvrf
почти 6 лет назад

Security update for apache-commons-beanutils

suse-cvrf
почти 6 лет назад

Security update for apache-commons-beanutils

EPSS

Процентиль: 54%
0.00317
Низкий

7.3 High

CVSS3