Vulnerability Description
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Commons Beanutils | >= 1.0, <= 1.9.3 |
| Apache | Nifi | 1.14.0 |
| Debian | Debian Linux | 8.0 |
| Opensuse | Leap | 15.0 |
| Fedoraproject | Fedora | 30 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Eus | 7.7 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server Aus | 7.7 |
| Redhat | Enterprise Linux Server Tus | 7.7 |
| Redhat | Enterprise Linux Workstation | 7.0 |
| Redhat | Jboss Enterprise Application Platform | 7.2.0 |
| Oracle | Agile Plm | 9.3.3 |
| Oracle | Agile Product Lifecycle Management Integration Pack | 3.5 |
| Oracle | Application Testing Suite | 13.3.0.1 |
| Oracle | Banking Platform | 2.4.0 |
| Oracle | Blockchain Platform | < 21.1.2 |
| Oracle | Communications Billing And Revenue Management | 7.5 |
| Oracle | Communications Billing And Revenue Management Elastic Charging Engine | 11.3.0.9 |
| Oracle | Communications Cloud Native Core Console | 1.4.0 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00007.htmlMailing ListThird Party Advisory
- http://mail-archives.apache.org/mod_mbox/www-announce/201908.mbox/%3cC628798F-31
- https://access.redhat.com/errata/RHSA-2019:4317Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0057Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0194Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0804Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0805Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0806Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0811Third Party Advisory
- https://lists.apache.org/thread.html/02094ad226dbc17a2368beaf27e61d8b1432f5baf77
- https://lists.apache.org/thread.html/1f78f1e32cc5614ec0c5b822ba4bd7fc8e8b5c46c8e
- https://lists.apache.org/thread.html/2fd61dc89df9aeab738d2b49f48d42c76f7d53b980b
- https://lists.apache.org/thread.html/3d1ed1a1596c08c4d5fea97b36c651ce167b773f1af
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e
- https://lists.apache.org/thread.html/5261066cd7adee081ee05c8bf0e96cf0b2eeaced391
FAQ
What is CVE-2019-10086?
CVE-2019-10086 is a vulnerability with a CVSS score of 7.3 (HIGH). In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Jav...
How severe is CVE-2019-10086?
CVE-2019-10086 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10086?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Commons Beanutils, Apache Nifi, Debian Debian Linux, Opensuse Leap, Fedoraproject Fedora.