VendorsApachecommons_beanutilsany version
Vulnerabilities

Apache Commons Beanutils any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2025-48734
Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default
Published 2025-05-28 · Modified
8.8EPSS 0.018
CVE-2014-0114
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.
Published 2014-04-30 · Modified
7.51 PoCEPSS 0.990
CVE-2019-10086
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
Published 2019-08-20 · Modified
7.5EPSS 0.284