CVE-2019-10086
7.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Exploitability: 3.9 / Impact: 3.4
Source: NVD
Description
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
Affected (106)
Show all products
Apache: Commons Beanutils, Nifi · Debian: Debian Linux · Opensuse: Leap · Fedoraproject: Fedora · Redhat: Enterprise Linux Desktop, Enterprise Linux Eus, Enterprise Linux Server Aus, Enterprise Linux Server Tus, Enterprise Linux Workstation, Jboss Enterprise Application Platform · Oracle: Agile Plm, Agile Product Lifecycle Management Integration Pack, Application Testing Suite, Banking Platform, Blockchain Platform, Communications Billing And Revenue Management, Communications Billing And Revenue Management Elastic Charging Engine, Communications Cloud Native Core Console, Communications Cloud Native Core Policy, Communications Cloud Native Core Unified Data Repository, Communications Convergence, Communications Design Studio, Communications Evolved Communications Application Server, Communications Metasolv Solution, Communications Network Integrity, Communications Performance Intelligence Center, Communications Pricing Design Center, Communications Unified Inventory Management, Customer Management And Segmentation Foundation, Enterprise Manager For Virtualization, Financial Services Revenue Management And Billing Analytics, Flexcube Private Banking, Fusion Middleware, Healthcare Foundation, Hospitality Opera 5, Hospitality Reporting And Analytics, Insurance Data Gateway, Jd Edwards Enterpriseone Orchestrator, Jd Edwards Enterpriseone Tools, Peoplesoft Enterprise Peopletools, Peoplesoft Enterprise Pt Peopletools, Primavera Gateway, Real Time Decisions Solutions, Retail Advanced Inventory Planning, Retail Back Office, Retail Central Office, Retail Invoice Matching, Retail Merchandising System, Retail Point Of Service, Retail Predictive Application Server, Retail Price Management, Retail Returns Management, Retail Xstore Point Of Service, Service Bus, Solaris Cluster, Time And Labor, Utilities Framework, Weblogic Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.9.3 | |
| Version 1.14.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 30 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.0 | |
| Version 7.7 | |
| Version 7.7 | |
| Version 7.7 | |
| Version 7.0 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.2.0 |
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux Server | Version 6.0 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.3.3 | |
| Version 3.5 | |
| Version 13.3.0.1 | |
| Version 2.4.0 | |
| Before 21.1.2 | |
| Version 12.0.0.3.0 | |
| Version 11.3.0.9 | |
| Version 1.4.0 | |
| Version 1.9.0 | |
| Version 1.6.0 | |
| Version 3.0.2.2.0 | |
| Version 7.3.4 | |
| Version 7.1 | |
| Version 6.3.0 | |
| Version 7.3.6 | |
| Version 10.4.0.3 | |
| Version 12.0.0.3.0 | |
| Version 7.3.4 | |
| Version 18.0 | |
| Version 13.4.0.0 | |
| Version 2.7 | |
| Version 12.0.0 | |
| Version 11.1.1.9 | |
| Version 7.1.5 | |
| Version 5.5 | |
| Version 9.1.0 | |
| Version 1.0.2.3 | |
| Before 9.2.5.3 | |
| Before 9.2.5.3 | |
| Version 8.56 | |
| Version 8.56 | |
| From 16.2.0 to 16.2.11 | |
| Version 3.2.0.0 | |
| Version 14.1 | |
| Version 14.1 | |
| Version 14.1 | |
| Version 16.0.3 | |
| Version 5.0.3.1 | |
| Version 14.1 | |
| Version 16.0 | |
| Version 14.0.1 | |
| Version 14.1 | |
| Version 15.0 | |
| Version 11.1.1.9.0 | |
| Version 4.4 | |
| From 12.2.6 to 12.2.11 | |
| From 4.3.0.1.0 to 4.3.0.6.0 | |
| Version 10.3.6.0.0 |
References (110)
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.