Количество 25
Количество 25
RLSA-2025:9318
Important: javapackages-tools:201801 security update
ELSA-2025-9318
ELSA-2025-9318: javapackages-tools:201801 security update (IMPORTANT)
CVE-2019-10086
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
CVE-2019-10086
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
CVE-2019-10086
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
CVE-2019-10086
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class wa ...
CVE-2025-48734
Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...
CVE-2025-48734
Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...
CVE-2025-48734
Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty()
CVE-2025-48734
Improper Access Control vulnerability in Apache Commons. A special ...
openSUSE-SU-2019:2058-1
Security update for apache-commons-beanutils
SUSE-SU-2019:2245-1
Security update for apache-commons-beanutils
SUSE-SU-2019:2244-1
Security update for apache-commons-beanutils
GHSA-6phf-73q6-gh87
Insecure Deserialization in Apache Commons Beanutils
ELSA-2020-0194
ELSA-2020-0194: apache-commons-beanutils security update (IMPORTANT)
BDU:2020-01020
Уязвимость класса BeanIntrospector утилиты Apache Commons Beanutils, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
SUSE-SU-2025:01815-1
Security update for apache-commons-beanutils
GHSA-wxr5-93ph-8wr9
Apache Commons Improper Access Control vulnerability
ELSA-2025-9166
ELSA-2025-9166: apache-commons-beanutils security update (IMPORTANT)
ELSA-2025-9114
ELSA-2025-9114: apache-commons-beanutils security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
RLSA-2025:9318 Important: javapackages-tools:201801 security update | около 1 года назад | |||
ELSA-2025-9318 ELSA-2025-9318: javapackages-tools:201801 security update (IMPORTANT) | около 1 года назад | |||
CVE-2019-10086 In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean. | CVSS3: 7.3 | 30% Средний | почти 7 лет назад | |
CVE-2019-10086 In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean. | CVSS3: 7.3 | 30% Средний | почти 7 лет назад | |
CVE-2019-10086 In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean. | CVSS3: 7.3 | 30% Средний | почти 7 лет назад | |
CVE-2019-10086 In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class wa ... | CVSS3: 7.3 | 30% Средний | почти 7 лет назад | |
CVE-2025-48734 Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta... | CVSS3: 8.8 | 2% Низкий | около 1 года назад | |
CVE-2025-48734 Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta... | CVSS3: 8.8 | 2% Низкий | около 1 года назад | |
CVE-2025-48734 Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty() | CVSS3: 8.8 | 2% Низкий | около 1 года назад | |
CVE-2025-48734 Improper Access Control vulnerability in Apache Commons. A special ... | CVSS3: 8.8 | 2% Низкий | около 1 года назад | |
openSUSE-SU-2019:2058-1 Security update for apache-commons-beanutils | 30% Средний | почти 7 лет назад | ||
SUSE-SU-2019:2245-1 Security update for apache-commons-beanutils | 30% Средний | почти 7 лет назад | ||
SUSE-SU-2019:2244-1 Security update for apache-commons-beanutils | 30% Средний | почти 7 лет назад | ||
GHSA-6phf-73q6-gh87 Insecure Deserialization in Apache Commons Beanutils | CVSS3: 7.3 | 30% Средний | около 6 лет назад | |
ELSA-2020-0194 ELSA-2020-0194: apache-commons-beanutils security update (IMPORTANT) | 30% Средний | больше 6 лет назад | ||
BDU:2020-01020 Уязвимость класса BeanIntrospector утилиты Apache Commons Beanutils, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации | CVSS3: 7.3 | 30% Средний | почти 7 лет назад | |
SUSE-SU-2025:01815-1 Security update for apache-commons-beanutils | 2% Низкий | около 1 года назад | ||
GHSA-wxr5-93ph-8wr9 Apache Commons Improper Access Control vulnerability | CVSS3: 8.8 | 2% Низкий | около 1 года назад | |
ELSA-2025-9166 ELSA-2025-9166: apache-commons-beanutils security update (IMPORTANT) | 2% Низкий | около 1 года назад | ||
ELSA-2025-9114 ELSA-2025-9114: apache-commons-beanutils security update (IMPORTANT) | 2% Низкий | около 1 года назад |
Уязвимостей на страницу