SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-10086

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects.

HIGH 7.3EPSS 29.2%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 29.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVSS 3.1
7.3 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS
29.24% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-502
Affected
apache/commons beanutils · apache/nifi · debian/debian linux · opensuse/leap · fedoraproject/fedora · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server tus · redhat/enterprise linux workstation · redhat/jboss enterprise application platform · oracle/agile product lifecycle management · oracle/agile product lifecycle management integration pack · oracle/application testing suite · oracle/banking platform · oracle/blockchain platform · oracle/communications billing and revenue management · oracle/communications billing and revenue management elastic charging engine · oracle/communications cloud native core console · +40 more
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.