← Back

CVE-2019-10086

nvd nist
Published: Aug 20, 2019Modified: Jun 17, 2026

JSON object

Loading...
7.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Exploitability: 3.9 / Impact: 3.4
Source: NVD

Description

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

Affected (106)

Show all products
Apache: Commons Beanutils, Nifi · Debian: Debian Linux · Opensuse: Leap · Fedoraproject: Fedora · Redhat: Enterprise Linux Desktop, Enterprise Linux Eus, Enterprise Linux Server Aus, Enterprise Linux Server Tus, Enterprise Linux Workstation, Jboss Enterprise Application Platform · Oracle: Agile Plm, Agile Product Lifecycle Management Integration Pack, Application Testing Suite, Banking Platform, Blockchain Platform, Communications Billing And Revenue Management, Communications Billing And Revenue Management Elastic Charging Engine, Communications Cloud Native Core Console, Communications Cloud Native Core Policy, Communications Cloud Native Core Unified Data Repository, Communications Convergence, Communications Design Studio, Communications Evolved Communications Application Server, Communications Metasolv Solution, Communications Network Integrity, Communications Performance Intelligence Center, Communications Pricing Design Center, Communications Unified Inventory Management, Customer Management And Segmentation Foundation, Enterprise Manager For Virtualization, Financial Services Revenue Management And Billing Analytics, Flexcube Private Banking, Fusion Middleware, Healthcare Foundation, Hospitality Opera 5, Hospitality Reporting And Analytics, Insurance Data Gateway, Jd Edwards Enterpriseone Orchestrator, Jd Edwards Enterpriseone Tools, Peoplesoft Enterprise Peopletools, Peoplesoft Enterprise Pt Peopletools, Primavera Gateway, Real Time Decisions Solutions, Retail Advanced Inventory Planning, Retail Back Office, Retail Central Office, Retail Invoice Matching, Retail Merchandising System, Retail Point Of Service, Retail Predictive Application Server, Retail Price Management, Retail Returns Management, Retail Xstore Point Of Service, Service Bus, Solaris Cluster, Time And Labor, Utilities Framework, Weblogic Server
2 products
Commons Beanutils
Nifi
1 product
Debian Linux
1 product
Leap
1 product
Fedora
6 products
Enterprise Linux Desktop
Enterprise Linux Eus
Enterprise Linux Server Aus
Enterprise Linux Server Tus
Enterprise Linux Workstation
48 products
Agile Plm
Application Testing Suite
Banking Platform
Blockchain Platform
Communications Convergence
Communications Design Studio
Communications Metasolv Solution
Communications Network Integrity
Flexcube Private Banking
Fusion Middleware
Healthcare Foundation
Hospitality Opera 5
Insurance Data Gateway
Jd Edwards Enterpriseone Tools
Peoplesoft Enterprise Peopletools
Primavera Gateway
Real Time Decisions Solutions
Retail Back Office
Retail Central Office
Retail Invoice Matching
Retail Merchandising System
Retail Point Of Service
Retail Price Management
Retail Returns Management
Retail Xstore Point Of Service
Service Bus
Solaris Cluster
Time And Labor
Utilities Framework
Weblogic Server
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
From 1.0 to 1.9.3
Apache
Version 1.14.0
Version 1.15.0
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 15.0
Version 15.1
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 30
Version 31
Configuration E
5 vulnerable
Configuration F
1 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
Version 7.2.0
Running on/withPlatform Versions
Redhat
Enterprise Linux Server
Version 6.0
Redhat
Enterprise Linux Server
Version 7.0
Redhat
Enterprise Linux Server
Version 8.0
Configuration G
92 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 9.3.3
Version 9.3.5
Version 9.3.6
Oracle
Version 3.5
Version 3.5
Version 3.6
Version 3.6
Version 13.3.0.1
Oracle
Version 2.4.0
Version 2.7.1
Version 2.9.0
Before 21.1.2
Oracle
Version 12.0.0.3.0
Version 7.5
Oracle
Version 11.3.0.9
Version 12.0.0.3
Version 1.4.0
Version 1.9.0
Version 1.6.0
Version 3.0.2.2.0
Oracle
Version 7.3.4
Version 7.3.5
Version 7.4.0
Version 7.1
Oracle
Version 6.3.0
Version 6.3.1
Version 7.3.6
Version 10.4.0.3
Version 12.0.0.3.0
Oracle
Version 7.3.4
Version 7.3.5
Version 7.4.0
Version 7.4.1
Version 18.0
Version 13.4.0.0
Oracle
Version 2.7
Version 2.8
Oracle
Version 12.0.0
Version 12.1.0
Oracle
Version 11.1.1.9
Version 12.2.1.3.0
Version 12.2.1.4.0
Oracle
Version 7.1.5
Version 7.2.2
Version 7.3.0
Version 7.3.1
Version 8.0.1
Oracle
Version 5.5
Version 5.6
Version 9.1.0
Version 1.0.2.3
Oracle
Before 9.2.5.3
Version 9.2.5.3
Oracle
Before 9.2.5.3
Version 9.2.5.3
Oracle
Version 8.56
Version 8.57
Oracle
Version 8.56
Version 8.57
Version 8.58
Oracle
From 16.2.0 to 16.2.11
From 17.12.0 to 17.12.6
Version 3.2.0.0
Version 14.1
Version 14.1
Version 14.1
Version 16.0.3
Version 5.0.3.1
Version 14.1
Version 16.0
Oracle
Version 14.0.1
Version 14.0
Version 15.0
Version 16.0
Version 14.1
Oracle
Version 15.0
Version 16.0
Version 17.0
Version 18.0
Version 7.1
Oracle
Version 11.1.1.9.0
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 4.4
From 12.2.6 to 12.2.11
Oracle
From 4.3.0.1.0 to 4.3.0.6.0
Version 4.2.0.2.0
Version 4.2.0.3.0
Version 4.4.0.0.0
Version 4.4.0.2.0
Version 4.4.0.3.0
Version 10.3.6.0.0

References (110)

Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.