cbcvebase.
CVE-2019-10086
published 2019-08-20

CVE-2019-10086: In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader…

PriorityP355high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
28.84%
97.9th percentile
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

Affected

107 ranges· showing 25
VendorProductVersion rangeFixed in
apacheapache_commons_beanutils
apachecommons_beanutils1.0 – 1.9.3
apachenifi
apachenifi
debiancommons-beanutils< commons-beanutils 1.9.4-1 (bookworm)commons-beanutils 1.9.4-1 (bookworm)
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
opensuseleap
opensuseleap
oracleagile_plm
oracleagile_plm
oracleagile_plm
oracleagile_product_lifecycle_management_integration_pack
oracleagile_product_lifecycle_management_integration_pack
oracleapplication_testing_suite
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oracleblockchain_platform< 21.1.221.1.2
oraclecommunications_billing_and_revenue_management
oraclecommunications_billing_and_revenue_management
oraclecommunications_billing_and_revenue_management_elastic_charging_engine
oraclecommunications_billing_and_revenue_management_elastic_charging_engine
oraclecommunications_cloud_native_core_console

CVSS provenance

nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.3HIGH
vendor_debian7.3HIGH
vendor_oracle7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.