CVE-2019-10086

Severity
7.3HIGH
EPSS
1.2%
top 20.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 20
Latest updateJul 15

Description

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 3.9 | Impact: 3.4

Affected Packages58 packages

NVDapache/commons_beanutils1.01.9.3
CVEListV5apache/apache_commons_beanutilsApache Commons Beanutils 1.0 to 1.9.3
Debiancommons-beanutils< 1.9.4-1+3
NVDapache/nifi1.14.0, 1.15.0+1

Also affects: Debian Linux 8.0, Fedora 30, 31, Enterprise Linux 7.7

Patches

🔴Vulnerability Details

4
GHSA
Insecure Deserialization in Apache Commons Beanutils2020-06-15
OSV
Insecure Deserialization in Apache Commons Beanutils2020-06-15
OSV
CVE-2019-10086: In Apache Commons Beanutils 12019-08-20
CVEList
CVE-2019-10086: In Apache Commons Beanutils 12019-08-20

📋Vendor Advisories

18
Oracle
Oracle Oracle Communications Risk Matrix: Security (Apache Commons BeanUtils) — CVE-2019-100862024-07-15
Oracle
Oracle Oracle Hyperion Risk Matrix: Security (Apache Commons BeanUtils) — CVE-2019-100862024-01-15
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Apache Commons BeanUtils) — CVE-2019-100862023-10-15
Oracle
Oracle Oracle Commerce Risk Matrix: Experience Manager, Platform Services (Apache Commons BeanUtils) — CVE-2019-100862023-07-15
Oracle
Oracle Oracle Analytics Risk Matrix: Analytics Server (Apache Commons BeanUtils) — CVE-2019-100862023-04-15

💬Community

2
Bugzilla
CVE-2019-10086 apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default [fedora-all]2019-10-31
Bugzilla
CVE-2019-10086 apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default2019-10-31