7.5

CVE-2019-10086

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheCommons Beanutils Version >= 1.0 <= 1.9.3
ApacheNifi Version1.14.0
ApacheNifi Version1.15.0
DebianDebian Linux Version8.0
OpensuseLeap Version15.0
OpensuseLeap Version15.1
FedoraprojectFedora Version30
FedoraprojectFedora Version31
RedhatEnterprise Linux Eus Version7.7
RedhatJboss Enterprise Application Platform Version7.2.0
   RedhatEnterprise Linux Server Version6.0
   RedhatEnterprise Linux Server Version7.0
   RedhatEnterprise Linux Server Version8.0
OracleAgile Plm Version9.3.3
OracleAgile Plm Version9.3.5
OracleAgile Plm Version9.3.6
OracleAgile Product Lifecycle Management Integration Pack Version3.5 SwPlatforme-business_suite
OracleAgile Product Lifecycle Management Integration Pack Version3.6 SwPlatforme-business_suite
OracleApplication Testing Suite Version13.3.0.1
OracleBanking Platform Version2.4.0
OracleBanking Platform Version2.7.1
OracleBanking Platform Version2.9.0
OracleBlockchain Platform Version < 21.1.2
OracleCommunications Convergence Version3.0.2.2.0
OracleFlexcube Private Banking Version12.0.0
OracleFlexcube Private Banking Version12.1.0
OracleFusion Middleware Version11.1.1.9
OracleFusion Middleware Version12.2.1.3.0
OracleFusion Middleware Version12.2.1.4.0
OracleHealthcare Foundation Version7.1.5
OracleHealthcare Foundation Version7.2.2
OracleHealthcare Foundation Version7.3.0
OracleHealthcare Foundation Version7.3.1
OracleHealthcare Foundation Version8.0.1
OracleHospitality Opera 5 Version5.5
OracleHospitality Opera 5 Version5.6
OracleInsurance Data Gateway Version1.0.2.3
OracleJd Edwards Enterpriseone Tools Version < 9.2.5.3
OraclePrimavera Gateway Version >= 16.2.0 <= 16.2.11
OraclePrimavera Gateway Version >= 17.12.0 <= 17.12.6
OracleRetail Back Office Version14.1
OracleRetail Central Office Version14.1
OracleRetail Invoice Matching Version16.0.3
OracleRetail Merchandising System Version5.0.3.1
OracleRetail Price Management Version14.0.1
OracleService Bus Version11.1.1.9.0
OracleService Bus Version12.2.1.3.0
OracleService Bus Version12.2.1.4.0
OracleSolaris Cluster Version4.4
OracleTime And Labor Version >= 12.2.6 <= 12.2.11
OracleUtilities Framework Version >= 4.3.0.1.0 <= 4.3.0.6.0
OracleUtilities Framework Version4.2.0.2.0
OracleUtilities Framework Version4.2.0.3.0
OracleUtilities Framework Version4.4.0.0.0
OracleUtilities Framework Version4.4.0.2.0
OracleUtilities Framework Version4.4.0.3.0
OracleWeblogic Server Version10.3.6.0.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.26% 0.489
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.3 3.9 3.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.