Логотип exploitDog
bind:"CVE-2019-10086" OR bind:"CVE-2025-48734"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2019-10086" OR bind:"CVE-2025-48734"

Количество 23

Количество 23

oracle-oval логотип

ELSA-2025-9318

около 1 месяца назад

ELSA-2025-9318: javapackages-tools:201801 security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2025-48734

2 месяца назад

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedPropert...

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2025-48734

2 месяца назад

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2025-48734

2 месяца назад

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty()

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2025-48734

2 месяца назад

Improper Access Control vulnerability in Apache Commons. A special ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2019-10086

почти 6 лет назад

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2019-10086

почти 6 лет назад

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2019-10086

почти 6 лет назад

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2019-10086

почти 6 лет назад

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class wa ...

CVSS3: 7.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2058-1

почти 6 лет назад

Security update for apache-commons-beanutils

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01815-1

2 месяца назад

Security update for apache-commons-beanutils

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2245-1

почти 6 лет назад

Security update for apache-commons-beanutils

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2244-1

почти 6 лет назад

Security update for apache-commons-beanutils

EPSS: Низкий
github логотип

GHSA-wxr5-93ph-8wr9

2 месяца назад

Apache Commons Improper Access Control vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-6phf-73q6-gh87

около 5 лет назад

Insecure Deserialization in Apache Commons Beanutils

CVSS3: 7.3
EPSS: Низкий
oracle-oval логотип

ELSA-2025-9166

около 1 месяца назад

ELSA-2025-9166: apache-commons-beanutils security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-9114

около 2 месяцев назад

ELSA-2025-9114: apache-commons-beanutils security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-0194

больше 5 лет назад

ELSA-2020-0194: apache-commons-beanutils security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2025-06231

2 месяца назад

Уязвимость класса PropertyUtilsBean утилиты Apache Commons Beanutils, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2020-01020

почти 6 лет назад

Уязвимость класса BeanIntrospector утилиты Apache Commons Beanutils, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2025-9318

ELSA-2025-9318: javapackages-tools:201801 security update (IMPORTANT)

около 1 месяца назад
ubuntu логотип
CVE-2025-48734

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedPropert...

CVSS3: 8.8
0%
Низкий
2 месяца назад
redhat логотип
CVE-2025-48734

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...

CVSS3: 8.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2025-48734

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty()

CVSS3: 8.8
0%
Низкий
2 месяца назад
debian логотип
CVE-2025-48734

Improper Access Control vulnerability in Apache Commons. A special ...

CVSS3: 8.8
0%
Низкий
2 месяца назад
ubuntu логотип
CVE-2019-10086

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVSS3: 7.3
0%
Низкий
почти 6 лет назад
redhat логотип
CVE-2019-10086

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVSS3: 7.3
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-10086

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVSS3: 7.3
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-10086

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class wa ...

CVSS3: 7.3
0%
Низкий
почти 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2058-1

Security update for apache-commons-beanutils

0%
Низкий
почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2025:01815-1

Security update for apache-commons-beanutils

0%
Низкий
2 месяца назад
suse-cvrf логотип
SUSE-SU-2019:2245-1

Security update for apache-commons-beanutils

0%
Низкий
почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2244-1

Security update for apache-commons-beanutils

0%
Низкий
почти 6 лет назад
github логотип
GHSA-wxr5-93ph-8wr9

Apache Commons Improper Access Control vulnerability

CVSS3: 8.8
0%
Низкий
2 месяца назад
github логотип
GHSA-6phf-73q6-gh87

Insecure Deserialization in Apache Commons Beanutils

CVSS3: 7.3
0%
Низкий
около 5 лет назад
oracle-oval логотип
ELSA-2025-9166

ELSA-2025-9166: apache-commons-beanutils security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2025-9114

ELSA-2025-9114: apache-commons-beanutils security update (IMPORTANT)

около 2 месяцев назад
oracle-oval логотип
ELSA-2020-0194

ELSA-2020-0194: apache-commons-beanutils security update (IMPORTANT)

больше 5 лет назад
fstec логотип
BDU:2025-06231

Уязвимость класса PropertyUtilsBean утилиты Apache Commons Beanutils, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
0%
Низкий
2 месяца назад
fstec логотип
BDU:2020-01020

Уязвимость класса BeanIntrospector утилиты Apache Commons Beanutils, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.3
0%
Низкий
почти 6 лет назад

Уязвимостей на страницу