Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade struts-manualUpgrade struts-javadocUpgrade strutsUpgrade struts-webapps-tomcat5 | Dec 1, 2016 | Apr 30, 2014 |
| Debian | — | Upgrade libstruts1.2-javaUpgrade commons-beanutils | Jul 30, 2024 | Apr 30, 2014 |
| Gentoo Linux | — | Upgrade dev-java/commons-beanutils. | Oct 30, 2017 | Apr 30, 2014 |
| Ibm Was | — | Upgrade to minimal fix pack levels as required by interim fixes and then apply latest Interim Fix. | Apr 27, 2018 | Apr 30, 2014 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 19182811 for version 12.1.3.0.0.Apply the Patch Set Update (PSU) 19182818 for version 12.1.1.0.0.Apply the Patch Set Update (PSU) 19182822 for version 12.1.2.0.0.Apply the Patch Set Update (PSU) 19182814 for version 10.3.6.0.0. | Apr 3, 2018 | Apr 30, 2014 |
| Oracle_linux | — | Upgrade struts-manualUpgrade struts-javadocUpgrade strutsUpgrade struts-webapps-tomcat5 | Oct 16, 2024 | Apr 30, 2014 |
| Struts | — | Migrate to Struts 2. | Jun 27, 2017 | Apr 30, 2014 |
| Suse | — | Upgrade apache-commons-beanutilsUpgrade struts-javadocUpgrade apache-commons-beanutils-javadocUpgrade struts-manualUpgrade struts | Dec 18, 2015 | Apr 30, 2014 |
| Ubuntu | — | Upgrade libcommons-beanutils-java-doc (Ubuntu Pro)Upgrade libcommons-beanutils-java (Ubuntu Pro) | Mar 22, 2023 | Apr 30, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub