QID 980293

QID 980293: Java (maven) Security Update for commons-beanutils:commons-beanutils (GHSA-6phf-73q6-gh87)

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.3 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer to GHSA-6phf-73q6-gh87 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980293

    Software Advisories
    Advisory ID Software Component Link
    GHSA-6phf-73q6-gh87 commons-beanutils:commons-beanutils URL Logo github.com/advisories/GHSA-6phf-73q6-gh87