VDB
RHSA-2020%3A2619
RHSA-2020%3A2619
PUBLISHED
CVSS 7.300000190734863 HIGH
A flaw was found in the Apache Commons BeanUtils, where the class property in PropertyUtilsBean is not suppressed by default. This flaw allows an attacker to access the classloader.
Risk Scores
CVSS 3.0
7.300000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Fuse 7.6.0 on EAP async |
Timeline
- Jun 19, 2020 CVE Published
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 14, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2020:2619 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/documentation/en-us/red_hat_fuse/7.6/ advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=jboss.fuse&downloadType=securityPatches&version=7.6.0 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1767483 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_2619.json advisory
- https://access.redhat.com/security/cve/CVE-2019-10086 advisory
- https://www.cve.org/CVERecord?id=CVE-2019-10086 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-10086 advisory
- https://commons.apache.org/proper/commons-beanutils/javadocs/v1.9.4/RELEASE-NOTES.txt advisory