PT-2019-4682 · Apache+7 · Apache Commons Beanutils+7
Published
2019-08-20
·
Updated
2026-05-19
·
CVE-2019-10086
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apache Commons Beanutils versions prior to 1.9.2
Description
The issue is related to the BeanIntrospector class in Apache Commons Beanutils, which can lead to the restoration of untrusted data structures in memory. This can allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. A special BeanIntrospector class was added in version 1.9.2 to suppress the ability for an attacker to access the classloader via the class property available on all Java objects.
Recommendations
For versions prior to 1.9.2, consider using the BeanIntrospector class to suppress the ability for an attacker to access the classloader via the class property available on all Java objects.
Update to version 1.9.2 or later, which includes the special BeanIntrospector class by default.
Fix
DoS
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Almalinux
Apache Commons Beanutils
Centos
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu