Логотип exploitDog
bind:"CVE-2025-48734"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2025-48734"

Количество 13

Количество 13

ubuntu логотип

CVE-2025-48734

2 месяца назад

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2025-48734

2 месяца назад

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2025-48734

2 месяца назад

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty()

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2025-48734

2 месяца назад

Improper Access Control vulnerability in Apache Commons. A special ...

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01815-1

2 месяца назад

Security update for apache-commons-beanutils

EPSS: Низкий
github логотип

GHSA-wxr5-93ph-8wr9

2 месяца назад

Apache Commons Improper Access Control vulnerability

CVSS3: 8.8
EPSS: Низкий
oracle-oval логотип

ELSA-2025-9166

около 1 месяца назад

ELSA-2025-9166: apache-commons-beanutils security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-9114

около 2 месяцев назад

ELSA-2025-9114: apache-commons-beanutils security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-10814

7 дней назад

ELSA-2025-10814: apache-commons-beanutils security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2025-06231

2 месяца назад

Уязвимость класса PropertyUtilsBean утилиты Apache Commons Beanutils, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20250710-11

27 дней назад

Уязвимость apache-commons-beanutils

CVSS3: 8.8
EPSS: Низкий
oracle-oval логотип

ELSA-2025-9318

около 1 месяца назад

ELSA-2025-9318: javapackages-tools:201801 security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02056-1

около 2 месяцев назад

Security update for apache-commons-beanutils

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-48734

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...

CVSS3: 8.8
0%
Низкий
2 месяца назад
redhat логотип
CVE-2025-48734

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...

CVSS3: 8.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2025-48734

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty()

CVSS3: 8.8
0%
Низкий
2 месяца назад
debian логотип
CVE-2025-48734

Improper Access Control vulnerability in Apache Commons. A special ...

CVSS3: 8.8
0%
Низкий
2 месяца назад
suse-cvrf логотип
SUSE-SU-2025:01815-1

Security update for apache-commons-beanutils

0%
Низкий
2 месяца назад
github логотип
GHSA-wxr5-93ph-8wr9

Apache Commons Improper Access Control vulnerability

CVSS3: 8.8
0%
Низкий
2 месяца назад
oracle-oval логотип
ELSA-2025-9166

ELSA-2025-9166: apache-commons-beanutils security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2025-9114

ELSA-2025-9114: apache-commons-beanutils security update (IMPORTANT)

около 2 месяцев назад
oracle-oval логотип
ELSA-2025-10814

ELSA-2025-10814: apache-commons-beanutils security update (IMPORTANT)

7 дней назад
fstec логотип
BDU:2025-06231

Уязвимость класса PropertyUtilsBean утилиты Apache Commons Beanutils, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
0%
Низкий
2 месяца назад
redos логотип
ROS-20250710-11

Уязвимость apache-commons-beanutils

CVSS3: 8.8
0%
Низкий
27 дней назад
oracle-oval логотип
ELSA-2025-9318

ELSA-2025-9318: javapackages-tools:201801 security update (IMPORTANT)

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2025:02056-1

Security update for apache-commons-beanutils

около 2 месяцев назад

Уязвимостей на страницу