Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 14

Количество 14

ubuntu логотип

CVE-2025-48734

около 1 года назад

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2025-48734

около 1 года назад

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2025-48734

около 1 года назад

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty()

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2025-48734

около 1 года назад

Improper Access Control vulnerability in Apache Commons. A special ...

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01815-1

около 1 года назад

Security update for apache-commons-beanutils

EPSS: Низкий
github логотип

GHSA-wxr5-93ph-8wr9

около 1 года назад

Apache Commons Improper Access Control vulnerability

CVSS3: 8.8
EPSS: Низкий
oracle-oval логотип

ELSA-2025-9166

около 1 года назад

ELSA-2025-9166: apache-commons-beanutils security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-9114

около 1 года назад

ELSA-2025-9114: apache-commons-beanutils security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-10814

около 1 года назад

ELSA-2025-10814: apache-commons-beanutils security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2025-06231

около 1 года назад

Уязвимость класса PropertyUtilsBean утилиты Apache Commons Beanutils, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20250710-11

около 1 года назад

Уязвимость apache-commons-beanutils

CVSS3: 8.8
EPSS: Низкий
rocky логотип

RLSA-2025:9318

около 1 года назад

Important: javapackages-tools:201801 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-9318

около 1 года назад

ELSA-2025-9318: javapackages-tools:201801 security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02056-1

около 1 года назад

Security update for apache-commons-beanutils

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-48734

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...

CVSS3: 8.8
2%
Низкий
около 1 года назад
redhat логотип
CVE-2025-48734

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...

CVSS3: 8.8
2%
Низкий
около 1 года назад
nvd логотип
CVE-2025-48734

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty()

CVSS3: 8.8
2%
Низкий
около 1 года назад
debian логотип
CVE-2025-48734

Improper Access Control vulnerability in Apache Commons. A special ...

CVSS3: 8.8
2%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:01815-1

Security update for apache-commons-beanutils

2%
Низкий
около 1 года назад
github логотип
GHSA-wxr5-93ph-8wr9

Apache Commons Improper Access Control vulnerability

CVSS3: 8.8
2%
Низкий
около 1 года назад
oracle-oval логотип
ELSA-2025-9166

ELSA-2025-9166: apache-commons-beanutils security update (IMPORTANT)

2%
Низкий
около 1 года назад
oracle-oval логотип
ELSA-2025-9114

ELSA-2025-9114: apache-commons-beanutils security update (IMPORTANT)

2%
Низкий
около 1 года назад
oracle-oval логотип
ELSA-2025-10814

ELSA-2025-10814: apache-commons-beanutils security update (IMPORTANT)

2%
Низкий
около 1 года назад
fstec логотип
BDU:2025-06231

Уязвимость класса PropertyUtilsBean утилиты Apache Commons Beanutils, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
2%
Низкий
около 1 года назад
redos логотип
ROS-20250710-11

Уязвимость apache-commons-beanutils

CVSS3: 8.8
2%
Низкий
около 1 года назад
rocky логотип
RLSA-2025:9318

Important: javapackages-tools:201801 security update

около 1 года назад
oracle-oval логотип
ELSA-2025-9318

ELSA-2025-9318: javapackages-tools:201801 security update (IMPORTANT)

около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:02056-1

Security update for apache-commons-beanutils

около 1 года назад

Уязвимостей на страницу