CVE-2019-10086
high · 7.3In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
7.3
CVSS
29.2%
EPSS (exploit prob.)
98th
EPSS percentile
2019-08-20
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Weaknesses
CWE-502
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | commons_beanutils | >= 1.0, <= 1.9.3 |
| apache | nifi | 1.14.0 |
| apache | nifi | 1.15.0 |
| debian | debian_linux | 8.0 |
| opensuse | leap | 15.0 |
| opensuse | leap | 15.1 |
| fedoraproject | fedora | 30 |
| fedoraproject | fedora | 31 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_eus | 7.7 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_aus | 7.7 |
| redhat | enterprise_linux_server_tus | 7.7 |
| redhat | enterprise_linux_workstation | 7.0 |
| redhat | jboss_enterprise_application_platform | 7.2.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server | 8.0 |
| oracle | agile_product_lifecycle_management | 9.3.3 |
| oracle | agile_product_lifecycle_management | 9.3.5 |
| oracle | agile_product_lifecycle_management | 9.3.6 |
| oracle | agile_product_lifecycle_management_integration_pack | 3.5 |
| oracle | agile_product_lifecycle_management_integration_pack | 3.5 |
| oracle | agile_product_lifecycle_management_integration_pack | 3.6 |
| oracle | agile_product_lifecycle_management_integration_pack | 3.6 |
| oracle | application_testing_suite | 13.3.0.1 |
| oracle | banking_platform | 2.4.0 |
| oracle | banking_platform | 2.7.1 |
| oracle | banking_platform | 2.9.0 |
| oracle | blockchain_platform | < 21.1.2 |
| oracle | communications_billing_and_revenue_management | 7.5 |
| oracle | communications_billing_and_revenue_management | 12.0.0.3.0 |
| oracle | communications_billing_and_revenue_management_elastic_charging_engine | 11.3.0.9 |
| oracle | communications_billing_and_revenue_management_elastic_charging_engine | 12.0.0.3 |
| oracle | communications_cloud_native_core_console | 1.4.0 |
| oracle | communications_cloud_native_core_policy | 1.9.0 |
| oracle | communications_cloud_native_core_unified_data_repository | 1.6.0 |
| oracle | communications_convergence | 3.0.2.2.0 |
| oracle | communications_design_studio | 7.3.4 |
| oracle | communications_design_studio | 7.3.5 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00007.html
- http://mail-archives.apache.org/mod_mbox/www-announce/201908.mbox/%3cC628798F-315D-4428-8CB1-4ED1ECC958E4%40apache.org%3e
- https://access.redhat.com/errata/RHSA-2019:4317
- https://access.redhat.com/errata/RHSA-2020:0057
- https://access.redhat.com/errata/RHSA-2020:0194
- https://access.redhat.com/errata/RHSA-2020:0804
- https://access.redhat.com/errata/RHSA-2020:0805
- https://access.redhat.com/errata/RHSA-2020:0806
- https://access.redhat.com/errata/RHSA-2020:0811
- https://lists.apache.org/thread.html/02094ad226dbc17a2368beaf27e61d8b1432f5baf77d0ca995bb78bc%40%3Cissues.commons.apache.org%3E
- https://lists.apache.org/thread.html/1f78f1e32cc5614ec0c5b822ba4bd7fc8e8b5c46c8e038b6bd609cb5%40%3Cissues.commons.apache.org%3E
- https://lists.apache.org/thread.html/2fd61dc89df9aeab738d2b49f48d42c76f7d53b980ba04e1d48bce48%40%3Cdev.shiro.apache.org%3E
- https://lists.apache.org/thread.html/3d1ed1a1596c08c4d5fea97b36c651ce167b773f1afc75251ce7a125%40%3Ccommits.tinkerpop.apache.org%3E
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/5261066cd7adee081ee05c8bf0e96cf0b2eeaced391e19117ae4daa6%40%3Cdev.shiro.apache.org%3E
- https://lists.apache.org/thread.html/956995acee0d8bc046f1df0a55b7fbeb65dd2f82864e5de1078bacb0%40%3Cissues.commons.apache.org%3E
- https://lists.apache.org/thread.html/a684107d3a78e431cf0fbb90629e8559a36ff8fe94c3a76e620b39fa%40%3Cdev.shiro.apache.org%3E
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/c94bc9649d5109a663b2129371dc45753fbdeacd340105548bbe93c3%40%3Cdev.shiro.apache.org%3E
- https://lists.apache.org/thread.html/d6ca9439c53374b597f33b7ec180001625597db48ea30356af01145f%40%3Cdev.shiro.apache.org%3E
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
- https://lists.apache.org/thread.html/r18d8b4f9263e5cad3bbaef0cdba0e2ccdf9201316ac4b85e23eb7ee4%40%3Cdev.atlas.apache.org%3E
- https://lists.apache.org/thread.html/r2d5f1d88c39bd615271abda63964a0bee9b2b57fef1f84cb4c43032e%40%3Cissues.nifi.apache.org%3E
- https://lists.apache.org/thread.html/r306c0322aa5c0da731e03f3ce9f07f4745c052c6b73f4e78faf232ca%40%3Cdev.atlas.apache.org%3E
- https://lists.apache.org/thread.html/r43de02fd4a4f52c4bdeff8c02f09625d83cd047498009c1cdab857db%40%3Cdev.rocketmq.apache.org%3E
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-10086