VDB
RHSA-2020%3A2619
RHSA-2020%3A2619
PUBLISHED
CVSS 7.300000190734863 HIGH
A flaw was found in the Apache Commons BeanUtils, where the class property in PropertyUtilsBean is not suppressed by default. This flaw allows an attacker to access the classloader.
Risk Scores
CVSS 3.0
7.300000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Fuse 7.6.0 on EAP async |
Timeline
- Jun 19, 2020 CVE Published
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 14, 2026 CVE Updated
- May 15, 2026 Distribution Patch
- May 15, 2026 Security Advisory
References
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/documentation/en-us/red_hat_fuse/7.6/ advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=jboss.fuse&downloadType=securityPatches&version=7.6.0 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_2619.json advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-10086 advisory
- https://access.redhat.com/errata/RHSA-2020:2619 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1767483 issue
- https://access.redhat.com/security/cve/CVE-2019-10086 advisory
- https://www.cve.org/CVERecord?id=CVE-2019-10086 advisory
- https://commons.apache.org/proper/commons-beanutils/javadocs/v1.9.4/RELEASE-NOTES.txt advisory