Количество 23
Количество 23
ELSA-2025-9318
ELSA-2025-9318: javapackages-tools:201801 security update (IMPORTANT)

CVE-2025-48734
Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedPropert...

CVE-2025-48734
Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...

CVE-2025-48734
Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty()
CVE-2025-48734
Improper Access Control vulnerability in Apache Commons. A special ...

CVE-2019-10086
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVE-2019-10086
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVE-2019-10086
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
CVE-2019-10086
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class wa ...

openSUSE-SU-2019:2058-1
Security update for apache-commons-beanutils

SUSE-SU-2025:01815-1
Security update for apache-commons-beanutils

SUSE-SU-2019:2245-1
Security update for apache-commons-beanutils

SUSE-SU-2019:2244-1
Security update for apache-commons-beanutils
GHSA-wxr5-93ph-8wr9
Apache Commons Improper Access Control vulnerability
GHSA-6phf-73q6-gh87
Insecure Deserialization in Apache Commons Beanutils
ELSA-2025-9166
ELSA-2025-9166: apache-commons-beanutils security update (IMPORTANT)
ELSA-2025-9114
ELSA-2025-9114: apache-commons-beanutils security update (IMPORTANT)
ELSA-2020-0194
ELSA-2020-0194: apache-commons-beanutils security update (IMPORTANT)

BDU:2025-06231
Уязвимость класса PropertyUtilsBean утилиты Apache Commons Beanutils, позволяющая нарушителю выполнить произвольный код

BDU:2020-01020
Уязвимость класса BeanIntrospector утилиты Apache Commons Beanutils, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
ELSA-2025-9318 ELSA-2025-9318: javapackages-tools:201801 security update (IMPORTANT) | около 1 месяца назад | |||
![]() | CVE-2025-48734 Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedPropert... | CVSS3: 8.8 | 0% Низкий | 2 месяца назад |
![]() | CVE-2025-48734 Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta... | CVSS3: 8.8 | 0% Низкий | 2 месяца назад |
![]() | CVE-2025-48734 Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty() | CVSS3: 8.8 | 0% Низкий | 2 месяца назад |
CVE-2025-48734 Improper Access Control vulnerability in Apache Commons. A special ... | CVSS3: 8.8 | 0% Низкий | 2 месяца назад | |
![]() | CVE-2019-10086 In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean. | CVSS3: 7.3 | 0% Низкий | почти 6 лет назад |
![]() | CVE-2019-10086 In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean. | CVSS3: 7.3 | 0% Низкий | почти 6 лет назад |
![]() | CVE-2019-10086 In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean. | CVSS3: 7.3 | 0% Низкий | почти 6 лет назад |
CVE-2019-10086 In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class wa ... | CVSS3: 7.3 | 0% Низкий | почти 6 лет назад | |
![]() | openSUSE-SU-2019:2058-1 Security update for apache-commons-beanutils | 0% Низкий | почти 6 лет назад | |
![]() | SUSE-SU-2025:01815-1 Security update for apache-commons-beanutils | 0% Низкий | 2 месяца назад | |
![]() | SUSE-SU-2019:2245-1 Security update for apache-commons-beanutils | 0% Низкий | почти 6 лет назад | |
![]() | SUSE-SU-2019:2244-1 Security update for apache-commons-beanutils | 0% Низкий | почти 6 лет назад | |
GHSA-wxr5-93ph-8wr9 Apache Commons Improper Access Control vulnerability | CVSS3: 8.8 | 0% Низкий | 2 месяца назад | |
GHSA-6phf-73q6-gh87 Insecure Deserialization in Apache Commons Beanutils | CVSS3: 7.3 | 0% Низкий | около 5 лет назад | |
ELSA-2025-9166 ELSA-2025-9166: apache-commons-beanutils security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2025-9114 ELSA-2025-9114: apache-commons-beanutils security update (IMPORTANT) | около 2 месяцев назад | |||
ELSA-2020-0194 ELSA-2020-0194: apache-commons-beanutils security update (IMPORTANT) | больше 5 лет назад | |||
![]() | BDU:2025-06231 Уязвимость класса PropertyUtilsBean утилиты Apache Commons Beanutils, позволяющая нарушителю выполнить произвольный код | CVSS3: 8.8 | 0% Низкий | 2 месяца назад |
![]() | BDU:2020-01020 Уязвимость класса BeanIntrospector утилиты Apache Commons Beanutils, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации | CVSS3: 7.3 | 0% Низкий | почти 6 лет назад |
Уязвимостей на страницу