Количество 10
Количество 10

CVE-2014-0114
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.

CVE-2014-0114
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.

CVE-2014-0114
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.
CVE-2014-0114
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8. ...
GHSA-p66x-2cv9-qq3v
Arbitrary code execution in Apache Commons BeanUtils
ELSA-2014-0474
ELSA-2014-0474: struts security update (IMPORTANT)

BDU:2015-04139
Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

BDU:2015-00729
Уязвимость программного обеспечения WebLogic Server, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

SUSE-SU-2015:0886-1
Security update for struts

SUSE-SU-2025:02056-1
Security update for apache-commons-beanutils
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2014-0114 Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1. | CVSS2: 7.5 | 92% Критический | больше 11 лет назад |
![]() | CVE-2014-0114 Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1. | CVSS2: 7.5 | 92% Критический | больше 11 лет назад |
![]() | CVE-2014-0114 Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1. | CVSS2: 7.5 | 92% Критический | больше 11 лет назад |
CVE-2014-0114 Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8. ... | CVSS2: 7.5 | 92% Критический | больше 11 лет назад | |
GHSA-p66x-2cv9-qq3v Arbitrary code execution in Apache Commons BeanUtils | 92% Критический | около 5 лет назад | ||
ELSA-2014-0474 ELSA-2014-0474: struts security update (IMPORTANT) | больше 11 лет назад | |||
![]() | BDU:2015-04139 Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации | CVSS2: 7.5 | 92% Критический | больше 11 лет назад |
![]() | BDU:2015-00729 Уязвимость программного обеспечения WebLogic Server, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации | CVSS2: 7.5 | 92% Критический | почти 11 лет назад |
![]() | SUSE-SU-2015:0886-1 Security update for struts | около 11 лет назад | ||
![]() | SUSE-SU-2025:02056-1 Security update for apache-commons-beanutils | 2 месяца назад |
Уязвимостей на страницу