CVE-2019-10086

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.3 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 58%
VendorProductVersion
apachecommons_beanutils
1.0 ≤
𝑥
≤ 1.9.3
apachenifi
1.14.0
apachenifi
1.15.0
debiandebian_linux
8.0
opensuseleap
15.0
opensuseleap
15.1
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_eus
7.7
redhatenterprise_linux_server
7.0
redhatenterprise_linux_server_aus
7.7
redhatenterprise_linux_server_tus
7.7
redhatenterprise_linux_workstation
7.0
redhatjboss_enterprise_application_platform
7.2.0
oracleagile_plm
9.3.3
oracleagile_plm
9.3.5
oracleagile_plm
9.3.6
oracleagile_product_lifecycle_management_integration_pack
3.5
oracleagile_product_lifecycle_management_integration_pack
3.5
oracleagile_product_lifecycle_management_integration_pack
3.6
oracleagile_product_lifecycle_management_integration_pack
3.6
oracleapplication_testing_suite
13.3.0.1
oraclebanking_platform
2.4.0
oraclebanking_platform
2.7.1
oraclebanking_platform
2.9.0
oracleblockchain_platform
𝑥
< 21.1.2
oraclecommunications_billing_and_revenue_management
7.5
oraclecommunications_billing_and_revenue_management
12.0.0.3.0
oraclecommunications_billing_and_revenue_management_elastic_charging_engine
11.3.0.9
oraclecommunications_billing_and_revenue_management_elastic_charging_engine
12.0.0.3
oraclecommunications_cloud_native_core_console
1.4.0
oraclecommunications_cloud_native_core_policy
1.9.0
oraclecommunications_cloud_native_core_unified_data_repository
1.6.0
oraclecommunications_convergence
3.0.2.2.0
oraclecommunications_design_studio
7.3.4
oraclecommunications_design_studio
7.3.5
oraclecommunications_design_studio
7.4.0
oraclecommunications_evolved_communications_application_server
7.1
oraclecommunications_metasolv_solution
6.3.0
oraclecommunications_metasolv_solution
6.3.1
oraclecommunications_network_integrity
7.3.6
oraclecommunications_performance_intelligence_center
10.4.0.3
oraclecommunications_pricing_design_center
12.0.0.3.0
oraclecommunications_unified_inventory_management
7.3.4
oraclecommunications_unified_inventory_management
7.3.5
oraclecommunications_unified_inventory_management
7.4.0
oraclecommunications_unified_inventory_management
7.4.1
oraclecustomer_management_and_segmentation_foundation
18.0
oracleenterprise_manager_for_virtualization
13.4.0.0
oraclefinancial_services_revenue_management_and_billing_analytics
2.7
oraclefinancial_services_revenue_management_and_billing_analytics
2.8
oracleflexcube_private_banking
12.0.0
oracleflexcube_private_banking
12.1.0
oraclefusion_middleware
11.1.1.9
oraclefusion_middleware
12.2.1.3.0
oraclefusion_middleware
12.2.1.4.0
oraclehealthcare_foundation
7.1.5
oraclehealthcare_foundation
7.2.2
oraclehealthcare_foundation
7.3.0
oraclehealthcare_foundation
7.3.1
oraclehealthcare_foundation
8.0.1
oraclehospitality_opera_5
5.5
oraclehospitality_opera_5
5.6
oraclehospitality_reporting_and_analytics
9.1.0
oracleinsurance_data_gateway
1.0.2.3
oraclejd_edwards_enterpriseone_orchestrator
𝑥
< 9.2.5.3
oraclejd_edwards_enterpriseone_orchestrator
9.2.5.3
oraclejd_edwards_enterpriseone_tools
𝑥
< 9.2.5.3
oraclejd_edwards_enterpriseone_tools
9.2.5.3
oraclepeoplesoft_enterprise_peopletools
8.56
oraclepeoplesoft_enterprise_peopletools
8.57
oraclepeoplesoft_enterprise_pt_peopletools
8.56
oraclepeoplesoft_enterprise_pt_peopletools
8.57
oraclepeoplesoft_enterprise_pt_peopletools
8.58
oracleprimavera_gateway
16.2.0 ≤
𝑥
≤ 16.2.11
oracleprimavera_gateway
17.12.0 ≤
𝑥
≤ 17.12.6
oraclereal-time_decisions_solutions
3.2.0.0
oracleretail_advanced_inventory_planning
14.1
oracleretail_back_office
14.1
oracleretail_central_office
14.1
oracleretail_invoice_matching
16.0.3
oracleretail_merchandising_system
5.0.3.1
oracleretail_point-of-service
14.1
oracleretail_predictive_application_server
16.0
oracleretail_price_management
14.0
oracleretail_price_management
14.0.1
oracleretail_price_management
15.0
oracleretail_price_management
16.0
oracleretail_returns_management
14.1
oracleretail_xstore_point_of_service
7.1
oracleretail_xstore_point_of_service
15.0
oracleretail_xstore_point_of_service
16.0
oracleretail_xstore_point_of_service
17.0
oracleretail_xstore_point_of_service
18.0
oracleservice_bus
11.1.1.9.0
oracleservice_bus
12.2.1.3.0
oracleservice_bus
12.2.1.4.0
oraclesolaris_cluster
4.4
oracletime_and_labor
12.2.6 ≤
𝑥
≤ 12.2.11
oracleutilities_framework
4.3.0.1.0 ≤
𝑥
≤ 4.3.0.6.0
oracleutilities_framework
4.2.0.2.0
oracleutilities_framework
4.2.0.3.0
oracleutilities_framework
4.4.0.0.0
oracleutilities_framework
4.4.0.2.0
oracleutilities_framework
4.4.0.3.0
oracleweblogic_server
10.3.6.0.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
commons-beanutils
bookworm
1.9.4-1
fixed
bullseye
1.9.4-1
fixed
buster
no-dsa
stretch
no-dsa
sid
1.9.4-2
fixed
trixie
1.9.4-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
commons-beanutils
lunar
not-affected
kinetic
not-affected
jammy
not-affected
impish
not-affected
hirsute
not-affected
groovy
not-affected
focal
not-affected
eoan
not-affected
disco
ignored
bionic
Fixed 1.9.3-1ubuntu0.1~esm1
released
xenial
Fixed 1.9.2-3ubuntu0.1~esm1
released
trusty
Fixed 1.9.1-1ubuntu0.1~esm1
released
References