Количество 13
Количество 13

CVE-2025-48734
Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...

CVE-2025-48734
Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...

CVE-2025-48734
Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty()
CVE-2025-48734
Improper Access Control vulnerability in Apache Commons. A special ...

SUSE-SU-2025:01815-1
Security update for apache-commons-beanutils
GHSA-wxr5-93ph-8wr9
Apache Commons Improper Access Control vulnerability
ELSA-2025-9166
ELSA-2025-9166: apache-commons-beanutils security update (IMPORTANT)
ELSA-2025-9114
ELSA-2025-9114: apache-commons-beanutils security update (IMPORTANT)
ELSA-2025-10814
ELSA-2025-10814: apache-commons-beanutils security update (IMPORTANT)

BDU:2025-06231
Уязвимость класса PropertyUtilsBean утилиты Apache Commons Beanutils, позволяющая нарушителю выполнить произвольный код

ROS-20250710-11
Уязвимость apache-commons-beanutils
ELSA-2025-9318
ELSA-2025-9318: javapackages-tools:201801 security update (IMPORTANT)

SUSE-SU-2025:02056-1
Security update for apache-commons-beanutils
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2025-48734 Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta... | CVSS3: 8.8 | 0% Низкий | 2 месяца назад |
![]() | CVE-2025-48734 Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta... | CVSS3: 8.8 | 0% Низкий | 2 месяца назад |
![]() | CVE-2025-48734 Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty() | CVSS3: 8.8 | 0% Низкий | 2 месяца назад |
CVE-2025-48734 Improper Access Control vulnerability in Apache Commons. A special ... | CVSS3: 8.8 | 0% Низкий | 2 месяца назад | |
![]() | SUSE-SU-2025:01815-1 Security update for apache-commons-beanutils | 0% Низкий | 2 месяца назад | |
GHSA-wxr5-93ph-8wr9 Apache Commons Improper Access Control vulnerability | CVSS3: 8.8 | 0% Низкий | 2 месяца назад | |
ELSA-2025-9166 ELSA-2025-9166: apache-commons-beanutils security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2025-9114 ELSA-2025-9114: apache-commons-beanutils security update (IMPORTANT) | около 2 месяцев назад | |||
ELSA-2025-10814 ELSA-2025-10814: apache-commons-beanutils security update (IMPORTANT) | 7 дней назад | |||
![]() | BDU:2025-06231 Уязвимость класса PropertyUtilsBean утилиты Apache Commons Beanutils, позволяющая нарушителю выполнить произвольный код | CVSS3: 8.8 | 0% Низкий | 2 месяца назад |
![]() | ROS-20250710-11 Уязвимость apache-commons-beanutils | CVSS3: 8.8 | 0% Низкий | 27 дней назад |
ELSA-2025-9318 ELSA-2025-9318: javapackages-tools:201801 security update (IMPORTANT) | около 1 месяца назад | |||
![]() | SUSE-SU-2025:02056-1 Security update for apache-commons-beanutils | около 2 месяцев назад |
Уязвимостей на страницу