← לוח פגיעויות

CVE-2019-10086

גבוהה 7.3

תיאור (מקור, אנגלית)

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

מדדים

CVSS 3.1
7.3 (HIGH) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS — סבירות ניצול
29% (אחוזון 100) נכון ל-16/9/2026
CWE
CWE-502

מוצרים מושפעים

apache: commons beanutils; apache: nifi; debian: debian linux; opensuse: leap; fedoraproject: fedora; redhat: enterprise linux desktop; redhat: enterprise linux eus; redhat: enterprise linux server; redhat: enterprise linux server aus; redhat: enterprise linux server tus; redhat: enterprise linux workstation; redhat: jboss enterprise application platform; oracle: agile product lifecycle management; oracle: agile product lifecycle management integration pack; oracle: application testing suite

קישורים