Логотип exploitDog
bind:"CVE-2019-10086" OR bind:"CVE-2025-48734"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2019-10086" OR bind:"CVE-2025-48734"

Количество 24

Количество 24

oracle-oval логотип

ELSA-2025-9318

4 месяца назад

ELSA-2025-9318: javapackages-tools:201801 security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2019-10086

около 6 лет назад

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2019-10086

около 6 лет назад

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2019-10086

около 6 лет назад

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2019-10086

около 6 лет назад

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class wa ...

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2025-48734

5 месяцев назад

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2025-48734

5 месяцев назад

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2025-48734

5 месяцев назад

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty()

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2025-48734

5 месяцев назад

Improper Access Control vulnerability in Apache Commons. A special ...

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2058-1

около 6 лет назад

Security update for apache-commons-beanutils

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2245-1

около 6 лет назад

Security update for apache-commons-beanutils

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2244-1

около 6 лет назад

Security update for apache-commons-beanutils

EPSS: Низкий
github логотип

GHSA-6phf-73q6-gh87

больше 5 лет назад

Insecure Deserialization in Apache Commons Beanutils

CVSS3: 7.3
EPSS: Низкий
oracle-oval логотип

ELSA-2020-0194

почти 6 лет назад

ELSA-2020-0194: apache-commons-beanutils security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2020-01020

около 6 лет назад

Уязвимость класса BeanIntrospector утилиты Apache Commons Beanutils, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01815-1

5 месяцев назад

Security update for apache-commons-beanutils

EPSS: Низкий
github логотип

GHSA-wxr5-93ph-8wr9

5 месяцев назад

Apache Commons Improper Access Control vulnerability

CVSS3: 8.8
EPSS: Низкий
oracle-oval логотип

ELSA-2025-9166

4 месяца назад

ELSA-2025-9166: apache-commons-beanutils security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-9114

5 месяцев назад

ELSA-2025-9114: apache-commons-beanutils security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-10814

3 месяца назад

ELSA-2025-10814: apache-commons-beanutils security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2025-9318

ELSA-2025-9318: javapackages-tools:201801 security update (IMPORTANT)

4 месяца назад
ubuntu логотип
CVE-2019-10086

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVSS3: 7.3
0%
Низкий
около 6 лет назад
redhat логотип
CVE-2019-10086

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVSS3: 7.3
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-10086

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVSS3: 7.3
0%
Низкий
около 6 лет назад
debian логотип
CVE-2019-10086

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class wa ...

CVSS3: 7.3
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2025-48734

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...

CVSS3: 8.8
0%
Низкий
5 месяцев назад
redhat логотип
CVE-2025-48734

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...

CVSS3: 8.8
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2025-48734

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty()

CVSS3: 8.8
0%
Низкий
5 месяцев назад
debian логотип
CVE-2025-48734

Improper Access Control vulnerability in Apache Commons. A special ...

CVSS3: 8.8
0%
Низкий
5 месяцев назад
suse-cvrf логотип
openSUSE-SU-2019:2058-1

Security update for apache-commons-beanutils

0%
Низкий
около 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2245-1

Security update for apache-commons-beanutils

0%
Низкий
около 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2244-1

Security update for apache-commons-beanutils

0%
Низкий
около 6 лет назад
github логотип
GHSA-6phf-73q6-gh87

Insecure Deserialization in Apache Commons Beanutils

CVSS3: 7.3
0%
Низкий
больше 5 лет назад
oracle-oval логотип
ELSA-2020-0194

ELSA-2020-0194: apache-commons-beanutils security update (IMPORTANT)

почти 6 лет назад
fstec логотип
BDU:2020-01020

Уязвимость класса BeanIntrospector утилиты Apache Commons Beanutils, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.3
0%
Низкий
около 6 лет назад
suse-cvrf логотип
SUSE-SU-2025:01815-1

Security update for apache-commons-beanutils

0%
Низкий
5 месяцев назад
github логотип
GHSA-wxr5-93ph-8wr9

Apache Commons Improper Access Control vulnerability

CVSS3: 8.8
0%
Низкий
5 месяцев назад
oracle-oval логотип
ELSA-2025-9166

ELSA-2025-9166: apache-commons-beanutils security update (IMPORTANT)

4 месяца назад
oracle-oval логотип
ELSA-2025-9114

ELSA-2025-9114: apache-commons-beanutils security update (IMPORTANT)

5 месяцев назад
oracle-oval логотип
ELSA-2025-10814

ELSA-2025-10814: apache-commons-beanutils security update (IMPORTANT)

3 месяца назад

Уязвимостей на страницу