Apache Commons Beanutils vulnerabilities
3 known vulnerabilities affecting apache/commons_beanutils.
Total CVEs
3
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH3
Vulnerabilities
Page 1 of 1
CVE-2025-48734HIGHCVSS 8.8≥ 1.0, < 1.11.0v2.0.02025-05-28
CVE-2025-48734 [HIGH] CWE-284 CVE-2025-48734: Improper Access Control vulnerability in Apache Commons.
A special BeanIntrospector class was add
Improper Access Control vulnerability in Apache Commons.
A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) n
nvd
CVE-2019-10086HIGHCVSS 7.3≥ 1.0, ≤ 1.9.32019-08-20
CVE-2019-10086 [HIGH] CWE-502 CVE-2019-10086: In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressi
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
nvd
CVE-2014-0114HIGHCVSS 7.5PoC≤ 1.9.12014-04-30
CVE-2014-0114 [HIGH] CWE-20 CVE-2014-0114: Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x thr
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the pass
nvd