In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Apache
Subscribe
|
|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Fedoraproject
Subscribe
|
Fedora
Subscribe
|
|
Opensuse
Subscribe
|
Leap
Subscribe
|
|
Oracle
Subscribe
|
Agile Plm
Subscribe
Agile Product Lifecycle Management Integration Pack
Subscribe
Application Testing Suite
Subscribe
Banking Platform
Subscribe
Blockchain Platform
Subscribe
Communications Billing And Revenue Management
Subscribe
Communications Billing And Revenue Management Elastic Charging Engine
Subscribe
Communications Cloud Native Core Console
Subscribe
Communications Cloud Native Core Policy
Subscribe
Communications Cloud Native Core Unified Data Repository
Subscribe
Communications Convergence
Subscribe
Communications Design Studio
Subscribe
Communications Evolved Communications Application Server
Subscribe
Communications Metasolv Solution
Subscribe
Communications Network Integrity
Subscribe
Communications Performance Intelligence Center
Subscribe
Communications Pricing Design Center
Subscribe
Communications Unified Inventory Management
Subscribe
Customer Management And Segmentation Foundation
Subscribe
Enterprise Manager For Virtualization
Subscribe
Financial Services Revenue Management And Billing Analytics
Subscribe
Flexcube Private Banking
Subscribe
Fusion Middleware
Subscribe
Healthcare Foundation
Subscribe
Hospitality Opera 5
Subscribe
Hospitality Reporting And Analytics
Subscribe
Insurance Data Gateway
Subscribe
Jd Edwards Enterpriseone Orchestrator
Subscribe
Jd Edwards Enterpriseone Tools
Subscribe
Peoplesoft Enterprise Peopletools
Subscribe
Peoplesoft Enterprise Pt Peopletools
Subscribe
Primavera Gateway
Subscribe
Real-time Decisions Solutions
Subscribe
Retail Advanced Inventory Planning
Subscribe
Retail Back Office
Subscribe
Retail Central Office
Subscribe
Retail Invoice Matching
Subscribe
Retail Merchandising System
Subscribe
Retail Point-of-service
Subscribe
Retail Predictive Application Server
Subscribe
Retail Price Management
Subscribe
Retail Returns Management
Subscribe
Retail Xstore Point Of Service
Subscribe
Service Bus
Subscribe
Solaris Cluster
Subscribe
Time And Labor
Subscribe
Utilities Framework
Subscribe
Weblogic Server
Subscribe
|
|
Redhat
Subscribe
|
Enterprise Linux
Subscribe
Enterprise Linux Desktop
Subscribe
Enterprise Linux Eus
Subscribe
Enterprise Linux Server
Subscribe
Enterprise Linux Server Aus
Subscribe
Enterprise Linux Server Tus
Subscribe
Enterprise Linux Workstation
Subscribe
Jboss Data Grid
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Application Platform Cd
Subscribe
Jboss Enterprise Application Platform Eus
Subscribe
Jboss Enterprise Bpms Platform
Subscribe
Jboss Enterprise Brms Platform
Subscribe
Jboss Fuse
Subscribe
Jboss Single Sign On
Subscribe
Openshift Application Runtimes
Subscribe
Rhel Software Collections
Subscribe
Rhev Manager
Subscribe
Satellite
Subscribe
Satellite Capsule
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1896-1 | commons-beanutils security update |
EUVD |
EUVD-2020-0465 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean. |
Github GHSA |
GHSA-6phf-73q6-gh87 | Insecure Deserialization in Apache Commons Beanutils |
Ubuntu USN |
USN-4766-1 | Apache Commons BeanUtils vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 23 Jun 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:enterprise_linux:8::crb |
Sun, 08 Dec 2024 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs |
Mon, 26 Aug 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat jboss Enterprise Application Platform Eus
|
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7 | |
| Vendors & Products |
Redhat jboss Enterprise Application Platform Eus
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T22:10:09.585Z
Reserved: 2019-03-26T00:00:00.000Z
Link: CVE-2019-10086
No data.
Status : Modified
Published: 2019-08-20T21:15:12.057
Modified: 2024-11-21T04:18:22.250
Link: CVE-2019-10086
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA
Ubuntu USN