FlawAtlas
Search the atlas
CVE-2019-10086 High

CVE-2019-10086

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

Exploit probability 29.8%
Published August 20, 2019
Required by Not available
Last source change July 8, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

2 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related ALSA-2025:9318
related CGA-5QMC-VXRJ-V4WW
related OPENSUSE-SU-2019:2058-1
related OPENSUSE-SU-2024:10617-1
related SUSE-SU-2019:2244-1
related SUSE-SU-2019:2245-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2019-10086

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

View original source

05 / REFERENCES

Further evidence