CVE Feed

    Dashboard / CVE / CVE-2019-10086

    CVE-2019-10086

    In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

    Published:Aug 15, 2019
    Last Modified:Aug 25, 2026
    EPS:Aug 20, 2019
    EPSS Score:0.29951
    CVSS Score:7.3

    Affected Products

    Vendor
    Apache
    Product
    Commons Beanutils
    Vendor
    Apache
    Product
    Nifi
    Vendor
    Debian
    Product
    Debian Linux
    Vendor
    Fedoraproject
    Product
    Fedora
    Vendor
    Opensuse
    Product
    Leap
    Vendor
    Oracle
    Product
    Agile Product Lifecycle Management
    Vendor
    Oracle
    Product
    Agile Product Lifecycle Management Integration Pack
    Vendor
    Oracle
    Product
    Application Testing Suite
    Vendor
    Oracle
    Product
    Banking Platform
    Vendor
    Oracle
    Product
    Blockchain Platform
    Vendor
    Oracle
    Product
    Communications Billing And Revenue Management
    Vendor
    Oracle
    Product
    Communications Billing And Revenue Management Elastic Charging Engine
    Vendor
    Oracle
    Product
    Communications Cloud Native Core Console
    Vendor
    Oracle
    Product
    Communications Cloud Native Core Policy
    Vendor
    Oracle
    Product
    Communications Cloud Native Core Unified Data Repository
    Vendor
    Oracle
    Product
    Communications Convergence
    Vendor
    Oracle
    Product
    Communications Design Studio
    Vendor
    Oracle
    Product
    Communications Evolved Communications Application Server
    Vendor
    Oracle
    Product
    Communications Metasolv Solution
    Vendor
    Oracle
    Product
    Communications Network Integrity
    Vendor
    Oracle
    Product
    Communications Performance Intelligence Center
    Vendor
    Oracle
    Product
    Communications Pricing Design Center
    Vendor
    Oracle
    Product
    Communications Unified Inventory Management
    Vendor
    Oracle
    Product
    Customer Management And Segmentation Foundation
    Vendor
    Oracle
    Product
    Enterprise Manager For Virtualization
    Vendor
    Oracle
    Product
    Financial Services Revenue Management And Billing Analytics
    Vendor
    Oracle
    Product
    Flexcube Private Banking
    Vendor
    Oracle
    Product
    Fusion Middleware
    Vendor
    Oracle
    Product
    Healthcare Foundation
    Vendor
    Oracle
    Product
    Hospitality Opera 5
    Vendor
    Oracle
    Product
    Hospitality Reporting And Analytics
    Vendor
    Oracle
    Product
    Insurance Data Gateway
    Vendor
    Oracle
    Product
    Jd Edwards Enterpriseone Orchestrator
    Vendor
    Oracle
    Product
    Jd Edwards Enterpriseone Tools
    Vendor
    Oracle
    Product
    Peoplesoft Enterprise Peopletools
    Vendor
    Oracle
    Product
    Peoplesoft Enterprise Pt Peopletools
    Vendor
    Oracle
    Product
    Primavera Gateway
    Vendor
    Oracle
    Product
    Real-time Decisions Solutions
    Vendor
    Oracle
    Product
    Retail Advanced Inventory Planning
    Vendor
    Oracle
    Product
    Retail Back Office
    Vendor
    Oracle
    Product
    Retail Central Office
    Vendor
    Oracle
    Product
    Retail Invoice Matching
    Vendor
    Oracle
    Product
    Retail Merchandising System
    Vendor
    Oracle
    Product
    Retail Point-of-service
    Vendor
    Oracle
    Product
    Retail Predictive Application Server
    Vendor
    Oracle
    Product
    Retail Price Management
    Vendor
    Oracle
    Product
    Retail Returns Management
    Vendor
    Oracle
    Product
    Retail Xstore Point Of Service
    Vendor
    Oracle
    Product
    Service Bus
    Vendor
    Oracle
    Product
    Solaris Cluster
    Vendor
    Oracle
    Product
    Time And Labor
    Vendor
    Oracle
    Product
    Utilities Framework
    Vendor
    Oracle
    Product
    Weblogic Server
    Vendor
    Redhat
    Product
    Enterprise Linux
    Vendor
    Redhat
    Product
    Enterprise Linux Desktop
    Vendor
    Redhat
    Product
    Enterprise Linux Eus
    Vendor
    Redhat
    Product
    Enterprise Linux Server
    Vendor
    Redhat
    Product
    Enterprise Linux Server Aus
    Vendor
    Redhat
    Product
    Enterprise Linux Server Tus
    Vendor
    Redhat
    Product
    Enterprise Linux Workstation
    Vendor
    Redhat
    Product
    Jboss Data Grid
    Vendor
    Redhat
    Product
    Jboss Enterprise Application Platform
    Vendor
    Redhat
    Product
    Jboss Enterprise Application Platform Cd
    Vendor
    Redhat
    Product
    Jboss Enterprise Application Platform Eus
    Vendor
    Redhat
    Product
    Jboss Enterprise Bpms Platform
    Vendor
    Redhat
    Product
    Jboss Enterprise Brms Platform
    Vendor
    Redhat
    Product
    Jboss Fuse
    Vendor
    Redhat
    Product
    Jboss Single Sign On
    Vendor
    Redhat
    Product
    Openshift Application Runtimes
    Vendor
    Redhat
    Product
    Rhel Software Collections
    Vendor
    Redhat
    Product
    Rhev Manager
    Vendor
    Redhat
    Product
    Satellite
    Vendor
    Redhat
    Product
    Satellite Capsule

    Common Attack Pattern Enumeration and Classification (CAPEC)

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High