← All CVEs

CVE-2019-10086

high · 7.3

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

7.3
CVSS
29.2%
EPSS (exploit prob.)
98th
EPSS percentile
2019-08-20
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Weaknesses

CWE-502

Affected products

VendorProductAffected versions
apachecommons_beanutils>= 1.0, <= 1.9.3
apachenifi1.14.0
apachenifi1.15.0
debiandebian_linux8.0
opensuseleap15.0
opensuseleap15.1
fedoraprojectfedora30
fedoraprojectfedora31
redhatenterprise_linux_desktop7.0
redhatenterprise_linux_eus7.7
redhatenterprise_linux_server7.0
redhatenterprise_linux_server_aus7.7
redhatenterprise_linux_server_tus7.7
redhatenterprise_linux_workstation7.0
redhatjboss_enterprise_application_platform7.2.0
redhatenterprise_linux_server6.0
redhatenterprise_linux_server7.0
redhatenterprise_linux_server8.0
oracleagile_product_lifecycle_management9.3.3
oracleagile_product_lifecycle_management9.3.5
oracleagile_product_lifecycle_management9.3.6
oracleagile_product_lifecycle_management_integration_pack3.5
oracleagile_product_lifecycle_management_integration_pack3.5
oracleagile_product_lifecycle_management_integration_pack3.6
oracleagile_product_lifecycle_management_integration_pack3.6
oracleapplication_testing_suite13.3.0.1
oraclebanking_platform2.4.0
oraclebanking_platform2.7.1
oraclebanking_platform2.9.0
oracleblockchain_platform< 21.1.2
oraclecommunications_billing_and_revenue_management7.5
oraclecommunications_billing_and_revenue_management12.0.0.3.0
oraclecommunications_billing_and_revenue_management_elastic_charging_engine11.3.0.9
oraclecommunications_billing_and_revenue_management_elastic_charging_engine12.0.0.3
oraclecommunications_cloud_native_core_console1.4.0
oraclecommunications_cloud_native_core_policy1.9.0
oraclecommunications_cloud_native_core_unified_data_repository1.6.0
oraclecommunications_convergence3.0.2.2.0
oraclecommunications_design_studio7.3.4
oraclecommunications_design_studio7.3.5

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-10086