PT-2019-4682 · Apache+7 · Apache Commons Beanutils+7

Published

2019-08-20

·

Updated

2026-05-19

·

CVE-2019-10086

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache Commons Beanutils versions prior to 1.9.2
Description The issue is related to the BeanIntrospector class in Apache Commons Beanutils, which can lead to the restoration of untrusted data structures in memory. This can allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. A special BeanIntrospector class was added in version 1.9.2 to suppress the ability for an attacker to access the classloader via the class property available on all Java objects.
Recommendations For versions prior to 1.9.2, consider using the BeanIntrospector class to suppress the ability for an attacker to access the classloader via the class property available on all Java objects. Update to version 1.9.2 or later, which includes the special BeanIntrospector class by default.

Fix

DoS

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

ALSA-2025:9318
BDU:2020-01020
CESA-2020_0194
CESA-2025_9318
CVE-2019-10086
DLA-1896-1
GHSA-6PHF-73Q6-GH87
INFSA-2025_9318
MGASA-2019-0399
OPENSUSE-SU-2019:2058-1
OPENSUSE-SU-2019_2058-1
OPENSUSE-SU-2024:10617-1
RHSA-2019:4317
RHSA-2020:0057
RHSA-2020:0194
RHSA-2020:0804
RHSA-2020:0805
RHSA-2020:0806
RHSA-2020:1308
RHSA-2020:1454
RHSA-2020:2740
RHSA-2020:3247
RHSA-2020_0194
RHSA-2024:5856
RHSA-2025:9318
RHSA-2025_9318
SUSE-SU-2019:2244-1
SUSE-SU-2019:2245-1
SUSE-SU-2019_2244-1
SUSE-SU-2019_2245-1
USN-4766-1

Affected Products

Almalinux
Apache Commons Beanutils
Centos
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu