Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 25

Количество 25

rocky логотип

RLSA-2025:9318

около 1 года назад

Important: javapackages-tools:201801 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-9318

около 1 года назад

ELSA-2025-9318: javapackages-tools:201801 security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2019-10086

почти 7 лет назад

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVSS3: 7.3
EPSS: Средний
redhat логотип

CVE-2019-10086

почти 7 лет назад

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVSS3: 7.3
EPSS: Средний
nvd логотип

CVE-2019-10086

почти 7 лет назад

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVSS3: 7.3
EPSS: Средний
debian логотип

CVE-2019-10086

почти 7 лет назад

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class wa ...

CVSS3: 7.3
EPSS: Средний
ubuntu логотип

CVE-2025-48734

около 1 года назад

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2025-48734

около 1 года назад

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2025-48734

около 1 года назад

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty()

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2025-48734

около 1 года назад

Improper Access Control vulnerability in Apache Commons. A special ...

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2058-1

почти 7 лет назад

Security update for apache-commons-beanutils

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2019:2245-1

почти 7 лет назад

Security update for apache-commons-beanutils

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2019:2244-1

почти 7 лет назад

Security update for apache-commons-beanutils

EPSS: Средний
github логотип

GHSA-6phf-73q6-gh87

около 6 лет назад

Insecure Deserialization in Apache Commons Beanutils

CVSS3: 7.3
EPSS: Средний
oracle-oval логотип

ELSA-2020-0194

больше 6 лет назад

ELSA-2020-0194: apache-commons-beanutils security update (IMPORTANT)

EPSS: Средний
fstec логотип

BDU:2020-01020

почти 7 лет назад

Уязвимость класса BeanIntrospector утилиты Apache Commons Beanutils, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.3
EPSS: Средний
suse-cvrf логотип

SUSE-SU-2025:01815-1

около 1 года назад

Security update for apache-commons-beanutils

EPSS: Низкий
github логотип

GHSA-wxr5-93ph-8wr9

около 1 года назад

Apache Commons Improper Access Control vulnerability

CVSS3: 8.8
EPSS: Низкий
oracle-oval логотип

ELSA-2025-9166

около 1 года назад

ELSA-2025-9166: apache-commons-beanutils security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-9114

около 1 года назад

ELSA-2025-9114: apache-commons-beanutils security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2025:9318

Important: javapackages-tools:201801 security update

около 1 года назад
oracle-oval логотип
ELSA-2025-9318

ELSA-2025-9318: javapackages-tools:201801 security update (IMPORTANT)

около 1 года назад
ubuntu логотип
CVE-2019-10086

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVSS3: 7.3
30%
Средний
почти 7 лет назад
redhat логотип
CVE-2019-10086

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVSS3: 7.3
30%
Средний
почти 7 лет назад
nvd логотип
CVE-2019-10086

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVSS3: 7.3
30%
Средний
почти 7 лет назад
debian логотип
CVE-2019-10086

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class wa ...

CVSS3: 7.3
30%
Средний
почти 7 лет назад
ubuntu логотип
CVE-2025-48734

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...

CVSS3: 8.8
2%
Низкий
около 1 года назад
redhat логотип
CVE-2025-48734

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...

CVSS3: 8.8
2%
Низкий
около 1 года назад
nvd логотип
CVE-2025-48734

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty()

CVSS3: 8.8
2%
Низкий
около 1 года назад
debian логотип
CVE-2025-48734

Improper Access Control vulnerability in Apache Commons. A special ...

CVSS3: 8.8
2%
Низкий
около 1 года назад
suse-cvrf логотип
openSUSE-SU-2019:2058-1

Security update for apache-commons-beanutils

30%
Средний
почти 7 лет назад
suse-cvrf логотип
SUSE-SU-2019:2245-1

Security update for apache-commons-beanutils

30%
Средний
почти 7 лет назад
suse-cvrf логотип
SUSE-SU-2019:2244-1

Security update for apache-commons-beanutils

30%
Средний
почти 7 лет назад
github логотип
GHSA-6phf-73q6-gh87

Insecure Deserialization in Apache Commons Beanutils

CVSS3: 7.3
30%
Средний
около 6 лет назад
oracle-oval логотип
ELSA-2020-0194

ELSA-2020-0194: apache-commons-beanutils security update (IMPORTANT)

30%
Средний
больше 6 лет назад
fstec логотип
BDU:2020-01020

Уязвимость класса BeanIntrospector утилиты Apache Commons Beanutils, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.3
30%
Средний
почти 7 лет назад
suse-cvrf логотип
SUSE-SU-2025:01815-1

Security update for apache-commons-beanutils

2%
Низкий
около 1 года назад
github логотип
GHSA-wxr5-93ph-8wr9

Apache Commons Improper Access Control vulnerability

CVSS3: 8.8
2%
Низкий
около 1 года назад
oracle-oval логотип
ELSA-2025-9166

ELSA-2025-9166: apache-commons-beanutils security update (IMPORTANT)

2%
Низкий
около 1 года назад
oracle-oval логотип
ELSA-2025-9114

ELSA-2025-9114: apache-commons-beanutils security update (IMPORTANT)

2%
Низкий
около 1 года назад

Уязвимостей на страницу