Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-10086


In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.


Published

2019-08-20T21:15:12.057

Last Modified

2024-11-21T04:18:22.250

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.3 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-502

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache commons_beanutils ≤ 1.9.3 Yes
Application apache nifi 1.14.0 Yes
Application apache nifi 1.15.0 Yes
Operating System debian debian_linux 8.0 Yes
Operating System opensuse leap 15.0 Yes
Operating System opensuse leap 15.1 Yes
Operating System fedoraproject fedora 30 Yes
Operating System fedoraproject fedora 31 Yes
Operating System redhat enterprise_linux_desktop 7.0 Yes
Operating System redhat enterprise_linux_eus 7.7 Yes
Operating System redhat enterprise_linux_server 7.0 Yes
Operating System redhat enterprise_linux_server_aus 7.7 Yes
Operating System redhat enterprise_linux_server_tus 7.7 Yes
Operating System redhat enterprise_linux_workstation 7.0 Yes
Application redhat jboss_enterprise_application_platform 7.2.0 Yes
Operating System redhat enterprise_linux_server 6.0 No
Operating System redhat enterprise_linux_server 7.0 No
Operating System redhat enterprise_linux_server 8.0 No
Application oracle agile_plm 9.3.3 Yes
Application oracle agile_plm 9.3.5 Yes
Application oracle agile_plm 9.3.6 Yes
Application oracle agile_product_lifecycle_management_integration_pack 3.5 Yes
Application oracle agile_product_lifecycle_management_integration_pack 3.5 Yes
Application oracle agile_product_lifecycle_management_integration_pack 3.6 Yes
Application oracle agile_product_lifecycle_management_integration_pack 3.6 Yes
Application oracle application_testing_suite 13.3.0.1 Yes
Application oracle banking_platform 2.4.0 Yes
Application oracle banking_platform 2.7.1 Yes
Application oracle banking_platform 2.9.0 Yes
Application oracle blockchain_platform < 21.1.2 Yes
Application oracle communications_billing_and_revenue_management 7.5 Yes
Application oracle communications_billing_and_revenue_management 12.0.0.3.0 Yes
Application oracle communications_billing_and_revenue_management_elastic_charging_engine 11.3.0.9 Yes
Application oracle communications_billing_and_revenue_management_elastic_charging_engine 12.0.0.3 Yes
Application oracle communications_cloud_native_core_console 1.4.0 Yes
Application oracle communications_cloud_native_core_policy 1.9.0 Yes
Application oracle communications_cloud_native_core_unified_data_repository 1.6.0 Yes
Application oracle communications_convergence 3.0.2.2.0 Yes
Application oracle communications_design_studio 7.3.4 Yes
Application oracle communications_design_studio 7.3.5 Yes
Application oracle communications_design_studio 7.4.0 Yes
Application oracle communications_evolved_communications_application_server 7.1 Yes
Application oracle communications_metasolv_solution 6.3.0 Yes
Application oracle communications_metasolv_solution 6.3.1 Yes
Application oracle communications_network_integrity 7.3.6 Yes
Application oracle communications_performance_intelligence_center 10.4.0.3 Yes
Application oracle communications_pricing_design_center 12.0.0.3.0 Yes
Application oracle communications_unified_inventory_management 7.3.4 Yes
Application oracle communications_unified_inventory_management 7.3.5 Yes
Application oracle communications_unified_inventory_management 7.4.0 Yes
Application oracle communications_unified_inventory_management 7.4.1 Yes
Application oracle customer_management_and_segmentation_foundation 18.0 Yes
Application oracle enterprise_manager_for_virtualization 13.4.0.0 Yes
Application oracle financial_services_revenue_management_and_billing_analytics 2.7 Yes
Application oracle financial_services_revenue_management_and_billing_analytics 2.8 Yes
Application oracle flexcube_private_banking 12.0.0 Yes
Application oracle flexcube_private_banking 12.1.0 Yes
Application oracle fusion_middleware 11.1.1.9 Yes
Application oracle fusion_middleware 12.2.1.3.0 Yes
Application oracle fusion_middleware 12.2.1.4.0 Yes
Application oracle healthcare_foundation 7.1.5 Yes
Application oracle healthcare_foundation 7.2.2 Yes
Application oracle healthcare_foundation 7.3.0 Yes
Application oracle healthcare_foundation 7.3.1 Yes
Application oracle healthcare_foundation 8.0.1 Yes
Application oracle hospitality_opera_5 5.5 Yes
Application oracle hospitality_opera_5 5.6 Yes
Application oracle hospitality_reporting_and_analytics 9.1.0 Yes
Application oracle insurance_data_gateway 1.0.2.3 Yes
Application oracle jd_edwards_enterpriseone_orchestrator < 9.2.5.3 Yes
Application oracle jd_edwards_enterpriseone_orchestrator 9.2.5.3 Yes
Application oracle jd_edwards_enterpriseone_tools < 9.2.5.3 Yes
Application oracle jd_edwards_enterpriseone_tools 9.2.5.3 Yes
Application oracle peoplesoft_enterprise_peopletools 8.56 Yes
Application oracle peoplesoft_enterprise_peopletools 8.57 Yes
Application oracle peoplesoft_enterprise_pt_peopletools 8.56 Yes
Application oracle peoplesoft_enterprise_pt_peopletools 8.57 Yes
Application oracle peoplesoft_enterprise_pt_peopletools 8.58 Yes
Application oracle primavera_gateway ≤ 16.2.11 Yes
Application oracle primavera_gateway ≤ 17.12.6 Yes
Application oracle real-time_decisions_solutions 3.2.0.0 Yes
Application oracle retail_advanced_inventory_planning 14.1 Yes
Application oracle retail_back_office 14.1 Yes
Application oracle retail_central_office 14.1 Yes
Application oracle retail_invoice_matching 16.0.3 Yes
Application oracle retail_merchandising_system 5.0.3.1 Yes
Application oracle retail_point-of-service 14.1 Yes
Application oracle retail_predictive_application_server 16.0 Yes
Application oracle retail_price_management 14.0 Yes
Application oracle retail_price_management 14.0.1 Yes
Application oracle retail_price_management 15.0 Yes
Application oracle retail_price_management 16.0 Yes
Application oracle retail_returns_management 14.1 Yes
Application oracle retail_xstore_point_of_service 7.1 Yes
Application oracle retail_xstore_point_of_service 15.0 Yes
Application oracle retail_xstore_point_of_service 16.0 Yes
Application oracle retail_xstore_point_of_service 17.0 Yes
Application oracle retail_xstore_point_of_service 18.0 Yes
Application oracle service_bus 11.1.1.9.0 Yes
Application oracle service_bus 12.2.1.3.0 Yes
Application oracle service_bus 12.2.1.4.0 Yes
Application oracle solaris_cluster 4.4 Yes
Application oracle time_and_labor ≤ 12.2.11 Yes
Application oracle utilities_framework ≤ 4.3.0.6.0 Yes
Application oracle utilities_framework 4.2.0.2.0 Yes
Application oracle utilities_framework 4.2.0.3.0 Yes
Application oracle utilities_framework 4.4.0.0.0 Yes
Application oracle utilities_framework 4.4.0.2.0 Yes
Application oracle utilities_framework 4.4.0.3.0 Yes
Application oracle weblogic_server 10.3.6.0.0 Yes

References