[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195549

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2020-1395 --- apache-commons-beanutils

ID: oval:org.secpod.oval:def:1700307Date: (C)2020-02-26   (M)2023-11-13
Class: PATCHFamily: unix




In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean

Platform:
Amazon Linux 2
Product:
apache-commons-beanutils
Reference:
ALAS2-2020-1395
CVE-2019-10086
CVE    1
CVE-2019-10086

© SecPod Technologies