CVE-2019-10086High· 7.3▾ TwilightIn Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.2 · likelihood 5.8 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
30%
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
commons_beanutils >= 1.0, <= 1.9.3nifi = 1.14.0nifi = 1.15.0debian_linux = 8.0leap = 15.0leap = 15.1fedora = 30fedora = 31enterprise_linux_desktop = 7.0enterprise_linux_eus = 7.7enterprise_linux_server = 7.0enterprise_linux_server_aus = 7.7enterprise_linux_server_tus = 7.7enterprise_linux_workstation = 7.0jboss_enterprise_application_platform = 7.2.0agile_product_lifecycle_management = 9.3.3agile_product_lifecycle_management = 9.3.5agile_product_lifecycle_management = 9.3.6agile_product_lifecycle_management_integration_pack = 3.5agile_product_lifecycle_management_integration_pack = 3.6application_testing_suite = 13.3.0.1banking_platform = 2.4.0banking_platform = 2.7.1banking_platform = 2.9.0blockchain_platform < 21.1.2communications_billing_and_revenue_management = 7.5communications_billing_and_revenue_management = 12.0.0.3.0communications_billing_and_revenue_management_elastic_charging_engine = 11.3.0.9communications_billing_and_revenue_management_elastic_charging_engine = 12.0.0.3communications_cloud_native_core_console = 1.4.0communications_cloud_native_core_policy = 1.9.0communications_cloud_native_core_unified_data_repository = 1.6.0communications_convergence = 3.0.2.2.0communications_design_studio = 7.3.4communications_design_studio = 7.3.5communications_design_studio = 7.4.0communications_evolved_communications_application_server = 7.1communications_metasolv_solution = 6.3.0communications_metasolv_solution = 6.3.1communications_network_integrity = 7.3.6communications_performance_intelligence_center = 10.4.0.3communications_pricing_design_center = 12.0.0.3.0communications_unified_inventory_management = 7.3.4communications_unified_inventory_management = 7.3.5communications_unified_inventory_management = 7.4.0communications_unified_inventory_management = 7.4.1customer_management_and_segmentation_foundation = 18.0enterprise_manager_for_virtualization = 13.4.0.0financial_services_revenue_management_and_billing_analytics = 2.7financial_services_revenue_management_and_billing_analytics = 2.8flexcube_private_banking = 12.0.0flexcube_private_banking = 12.1.0fusion_middleware = 11.1.1.9fusion_middleware = 12.2.1.3.0fusion_middleware = 12.2.1.4.0healthcare_foundation = 7.1.5healthcare_foundation = 7.2.2healthcare_foundation = 7.3.0healthcare_foundation = 7.3.1healthcare_foundation = 8.0.1hospitality_opera_5 = 5.5hospitality_opera_5 = 5.6hospitality_reporting_and_analytics = 9.1.0insurance_data_gateway = 1.0.2.3jd_edwards_enterpriseone_orchestrator < 9.2.5.3jd_edwards_enterpriseone_orchestrator = 9.2.5.3jd_edwards_enterpriseone_tools < 9.2.5.3jd_edwards_enterpriseone_tools = 9.2.5.3peoplesoft_enterprise_peopletools = 8.56peoplesoft_enterprise_peopletools = 8.57peoplesoft_enterprise_pt_peopletools = 8.56peoplesoft_enterprise_pt_peopletools = 8.57peoplesoft_enterprise_pt_peopletools = 8.58primavera_gateway >= 16.2.0, <= 16.2.11primavera_gateway >= 17.12.0, <= 17.12.6real-time_decisions_solutions = 3.2.0.0retail_advanced_inventory_planning = 14.1retail_back_office = 14.1retail_central_office = 14.1retail_invoice_matching = 16.0.3retail_merchandising_system = 5.0.3.1retail_point-of-service = 14.1retail_predictive_application_server = 16.0retail_price_management = 14.0retail_price_management = 14.0.1retail_price_management = 15.0retail_price_management = 16.0retail_returns_management = 14.1retail_xstore_point_of_service = 7.1retail_xstore_point_of_service = 15.0retail_xstore_point_of_service = 16.0retail_xstore_point_of_service = 17.0retail_xstore_point_of_service = 18.0service_bus = 11.1.1.9.0service_bus = 12.2.1.3.0service_bus = 12.2.1.4.0solaris_cluster = 4.4time_and_labor >= 12.2.6, <= 12.2.11utilities_framework >= 4.3.0.1.0, <= 4.3.0.6.0utilities_framework = 4.2.0.2.0Upgrade past the affected range:
blockchain_platform 21.1.2jd_edwards_enterpriseone_orchestrator 9.2.5.3jd_edwards_enterpriseone_tools 9.2.5.3Connected by shared product, vendor, weakness, or advisory.
CVE-2020-9484High· 7.0When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use…
CVE-2020-36182High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.
CVE-2020-36180High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.
CVE-2020-36179High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.
CVE-2020-36184High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.
CVE-2020-36181High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS.