CVE-2019-10086

🟡 Monitoruj

Luka w Apache Commons Beanutils umożliwia atakującym dostęp do classloadera przez właściwości klas.

CVSS: źródło nieustalone · szczegóły: D1

CVSS
7.3
EPSS
28.4%
Exploit
none
Vendor
oracle
Opis źródłowy (NVD)

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

brak Status patcha: nieustalony
Źródła i daty
ŹródłoWartość
NVD – CVSS 7.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS · ocena nieustalona28.4%
Opublikowano (NVD)2019-08-20 21:15:12 UTC
Ostatnia modyfikacja (NVD)2026-10-08 22:16:48 UTC
Referencje