VYPR

rpm package

suse/apache-commons-beanutils&distro=SUSE Linux Enterprise Server LTSS Extended Security 12 SP5

pkg:rpm/suse/apache-commons-beanutils&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5

Vulnerabilities (3)

  • CVE-2025-48734May 28, 2025
    affected < 1.11.0-7.3.1fixed 1.11.0-7.3.1

    Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was no

  • CVE-2015-4852CriKEVNov 18, 2015
    affected < 1.11.0-7.3.1fixed 1.11.0-7.3.1

    The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache

  • CVE-2014-0114Apr 30, 2014
    affected < 1.11.0-7.3.1fixed 1.11.0-7.3.1

    Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and