GHSA-6phf-73q6-gh87 · Severity: high · Ecosystem: maven — Insecure Deserialization in Apache Commons Beanutils
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
Conclusion & alert: CVE-2019-10086 is rated Moderate Risk (57.8/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.24%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-04 | 0.26% | 1.24% | +0.98% |
| 2 | 2025-11-21 | 1.63% | 0.26% | -1.37% |
| 3 | 2025-11-18 | — | 1.63% | — |
Full EPSS history (24 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.3 | 3.1 | HIGH |
|
3.9 | 3.4 | [email protected] |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
GHSA-6phf-73q6-gh87 · Severity: high · Ecosystem: maven — Insecure Deserialization in Apache Commons Beanutils
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2019-10086 not yet assigned priority: Debian including 1 source packages (commons-beanutils), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2019-10086 |
gentoo
|
normal | CVE-2019-10086: 1 GLSA(s) (202405-21), 1 atom(s) (dev-java/commons-beanutils); latest impact normal. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2019-10086 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2019-10086 |
suse
|
high | CVE-2019-10086 severity important: SUSE including 755 source package names (amazon/suse-sles-15-sp1-chost-byos-v20210304-hvm-ssd-x86_64, amazon/suse-sles-15-sp1-chost-byos-v20220127-hvm-ssd-x86_64, …), 768 product×package rows across 17 product lines (SUSE Liberty Linux 7, SUSE Liberty Linux 7 LTSS, … (17 product lines)): Fixed 536, Known Affected 231, Known Not Affected 1. | https://www.suse.com/security/cve/CVE-2019-10086/ |
ubuntu
|
medium | CVE-2019-10086 medium priority: Ubuntu including 1 source packages (commons-beanutils), 13 status rows across 13 suites (bionic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, trusty, upstream, xenial): not-affected 8, released 4, ignored 1. | https://ubuntu.com/security/CVE-2019-10086 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | commons_beanutils | >= 1.0, <= 1.9.3 | cpe:2.3:a:apache:commons_beanutils:*:*:*:*:*:*:*:* |
| apache | nifi | 1.14.0 | cpe:2.3:a:apache:nifi:1.14.0:*:*:*:*:*:*:* |
| apache | nifi | 1.15.0 | cpe:2.3:a:apache:nifi:1.15.0:*:*:*:*:*:*:* |
| debian | debian_linux | 8.0 | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
| opensuse | leap | 15.0 | cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:* |
| opensuse | leap | 15.1 | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* |
| fedoraproject | fedora | 30 | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* |
| fedoraproject | fedora | 31 | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* |
| redhat | enterprise_linux_desktop | 7.0 | cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_eus | 7.7 | cpe:2.3:o:redhat:enterprise_linux_eus:7.7:*:*:*:*:*:*:* |
| redhat | enterprise_linux_server | 7.0 | cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_server_aus | 7.7 | cpe:2.3:o:redhat:enterprise_linux_server_aus:7.7:*:*:*:*:*:*:* |
| redhat | enterprise_linux_server_tus | 7.7 | cpe:2.3:o:redhat:enterprise_linux_server_tus:7.7:*:*:*:*:*:*:* |
| redhat | enterprise_linux_workstation | 7.0 | cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:* |
| redhat | jboss_enterprise_application_platform | 7.2.0 | cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2.0:*:*:*:*:*:*:* |
| oracle | agile_plm | 9.3.3 | cpe:2.3:a:oracle:agile_plm:9.3.3:*:*:*:*:*:*:* |
| oracle | agile_plm | 9.3.5 | cpe:2.3:a:oracle:agile_plm:9.3.5:*:*:*:*:*:*:* |
| oracle | agile_plm | 9.3.6 | cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:* |
| oracle | agile_product_lifecycle_management_integration_pack | 3.5 | cpe:2.3:a:oracle:agile_product_lifecycle_management_integration_pack:3.5:*:*:*:*:e-business_suite:*:* |
| oracle | agile_product_lifecycle_management_integration_pack | 3.5 | cpe:2.3:a:oracle:agile_product_lifecycle_management_integration_pack:3.5:*:*:*:*:sap:*:* |
| oracle | agile_product_lifecycle_management_integration_pack | 3.6 | cpe:2.3:a:oracle:agile_product_lifecycle_management_integration_pack:3.6:*:*:*:*:e-business_suite:*:* |
| oracle | agile_product_lifecycle_management_integration_pack | 3.6 | cpe:2.3:a:oracle:agile_product_lifecycle_management_integration_pack:3.6:*:*:*:*:sap:*:* |
| oracle | application_testing_suite | 13.3.0.1 | cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:* |
| oracle | banking_platform | 2.4.0 | cpe:2.3:a:oracle:banking_platform:2.4.0:*:*:*:*:*:*:* |
| oracle | banking_platform | 2.7.1 | cpe:2.3:a:oracle:banking_platform:2.7.1:*:*:*:*:*:*:* |
| oracle | banking_platform | 2.9.0 | cpe:2.3:a:oracle:banking_platform:2.9.0:*:*:*:*:*:*:* |
| oracle | blockchain_platform | < 21.1.2 | cpe:2.3:a:oracle:blockchain_platform:*:*:*:*:*:*:*:* |
| oracle | communications_billing_and_revenue_management | 7.5 | cpe:2.3:a:oracle:communications_billing_and_revenue_management:7.5:*:*:*:*:*:*:* |
| oracle | communications_billing_and_revenue_management | 12.0.0.3.0 | cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.3.0:*:*:*:*:*:*:* |
| oracle | communications_billing_and_revenue_management_elastic_charging_engine | 11.3.0.9 | cpe:2.3:a:oracle:communications_billing_and_revenue_management_elastic_charging_engine:11.3.0.9:*:*:*:*:*:*:* |
| oracle | communications_billing_and_revenue_management_elastic_charging_engine | 12.0.0.3 | cpe:2.3:a:oracle:communications_billing_and_revenue_management_elastic_charging_engine:12.0.0.3:*:*:*:*:*:*:* |
| oracle | communications_cloud_native_core_console | 1.4.0 | cpe:2.3:a:oracle:communications_cloud_native_core_console:1.4.0:*:*:*:*:*:*:* |
| oracle | communications_cloud_native_core_policy | 1.9.0 | cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.9.0:*:*:*:*:*:*:* |
| oracle | communications_cloud_native_core_unified_data_repository | 1.6.0 | cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:1.6.0:*:*:*:*:*:*:* |
| oracle | communications_convergence | 3.0.2.2.0 | cpe:2.3:a:oracle:communications_convergence:3.0.2.2.0:*:*:*:*:*:*:* |
| oracle | communications_design_studio | 7.3.4 | cpe:2.3:a:oracle:communications_design_studio:7.3.4:*:*:*:*:*:*:* |
| oracle | communications_design_studio | 7.3.5 | cpe:2.3:a:oracle:communications_design_studio:7.3.5:*:*:*:*:*:*:* |
| oracle | communications_design_studio | 7.4.0 | cpe:2.3:a:oracle:communications_design_studio:7.4.0:*:*:*:*:*:*:* |
| oracle | communications_evolved_communications_application_server | 7.1 | cpe:2.3:a:oracle:communications_evolved_communications_application_server:7.1:*:*:*:*:*:*:* |
| oracle | communications_metasolv_solution | 6.3.0 | cpe:2.3:a:oracle:communications_metasolv_solution:6.3.0:*:*:*:*:*:*:* |
| oracle | communications_metasolv_solution | 6.3.1 | cpe:2.3:a:oracle:communications_metasolv_solution:6.3.1:*:*:*:*:*:*:* |
| oracle | communications_network_integrity | 7.3.6 | cpe:2.3:a:oracle:communications_network_integrity:7.3.6:*:*:*:*:*:*:* |
| oracle | communications_performance_intelligence_center | 10.4.0.3 | cpe:2.3:a:oracle:communications_performance_intelligence_center:10.4.0.3:*:*:*:*:*:*:* |
| oracle | communications_pricing_design_center | 12.0.0.3.0 | cpe:2.3:a:oracle:communications_pricing_design_center:12.0.0.3.0:*:*:*:*:*:*:* |
| oracle | communications_unified_inventory_management | 7.3.4 | cpe:2.3:a:oracle:communications_unified_inventory_management:7.3.4:*:*:*:*:*:*:* |
| oracle | communications_unified_inventory_management | 7.3.5 | cpe:2.3:a:oracle:communications_unified_inventory_management:7.3.5:*:*:*:*:*:*:* |
| oracle | communications_unified_inventory_management | 7.4.0 | cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.0:*:*:*:*:*:*:* |
| oracle | communications_unified_inventory_management | 7.4.1 | cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.1:*:*:*:*:*:*:* |
| oracle | customer_management_and_segmentation_foundation | 18.0 | cpe:2.3:a:oracle:customer_management_and_segmentation_foundation:18.0:*:*:*:*:*:*:* |
| oracle | enterprise_manager_for_virtualization | 13.4.0.0 | cpe:2.3:a:oracle:enterprise_manager_for_virtualization:13.4.0.0:*:*:*:*:*:*:* |
| oracle | financial_services_revenue_management_and_billing_analytics | 2.7 | cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.7:*:*:*:*:*:*:* |
| oracle | financial_services_revenue_management_and_billing_analytics | 2.8 | cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.8:*:*:*:*:*:*:* |
| oracle | flexcube_private_banking | 12.0.0 | cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:* |
| oracle | flexcube_private_banking | 12.1.0 | cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:* |
| oracle | fusion_middleware | 11.1.1.9 | cpe:2.3:a:oracle:fusion_middleware:11.1.1.9:*:*:*:*:*:*:* |
| oracle | fusion_middleware | 12.2.1.3.0 | cpe:2.3:a:oracle:fusion_middleware:12.2.1.3.0:*:*:*:*:*:*:* |
| oracle | fusion_middleware | 12.2.1.4.0 | cpe:2.3:a:oracle:fusion_middleware:12.2.1.4.0:*:*:*:*:*:*:* |
| oracle | healthcare_foundation | 7.1.5 | cpe:2.3:a:oracle:healthcare_foundation:7.1.5:*:*:*:*:*:*:* |
| oracle | healthcare_foundation | 7.2.2 | cpe:2.3:a:oracle:healthcare_foundation:7.2.2:*:*:*:*:*:*:* |
| oracle | healthcare_foundation | 7.3.0 | cpe:2.3:a:oracle:healthcare_foundation:7.3.0:*:*:*:*:*:*:* |
| oracle | healthcare_foundation | 7.3.1 | cpe:2.3:a:oracle:healthcare_foundation:7.3.1:*:*:*:*:*:*:* |
| oracle | healthcare_foundation | 8.0.1 | cpe:2.3:a:oracle:healthcare_foundation:8.0.1:*:*:*:*:*:*:* |
| oracle | hospitality_opera_5 | 5.5 | cpe:2.3:a:oracle:hospitality_opera_5:5.5:*:*:*:*:*:*:* |
| oracle | hospitality_opera_5 | 5.6 | cpe:2.3:a:oracle:hospitality_opera_5:5.6:*:*:*:*:*:*:* |
| oracle | hospitality_reporting_and_analytics | 9.1.0 | cpe:2.3:a:oracle:hospitality_reporting_and_analytics:9.1.0:*:*:*:*:*:*:* |
| oracle | insurance_data_gateway | 1.0.2.3 | cpe:2.3:a:oracle:insurance_data_gateway:1.0.2.3:*:*:*:*:*:*:* |
| oracle | jd_edwards_enterpriseone_orchestrator | < 9.2.5.3 | cpe:2.3:a:oracle:jd_edwards_enterpriseone_orchestrator:*:*:*:*:*:*:*:* |
| oracle | jd_edwards_enterpriseone_orchestrator | 9.2.5.3 | cpe:2.3:a:oracle:jd_edwards_enterpriseone_orchestrator:9.2.5.3:*:*:*:*:*:*:* |
| oracle | jd_edwards_enterpriseone_tools | < 9.2.5.3 | cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:* |
| oracle | jd_edwards_enterpriseone_tools | 9.2.5.3 | cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2.5.3:*:*:*:*:*:*:* |
| oracle | peoplesoft_enterprise_peopletools | 8.56 | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:* |
| oracle | peoplesoft_enterprise_peopletools | 8.57 | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:* |
| oracle | peoplesoft_enterprise_pt_peopletools | 8.56 | cpe:2.3:a:oracle:peoplesoft_enterprise_pt_peopletools:8.56:*:*:*:*:*:*:* |
| oracle | peoplesoft_enterprise_pt_peopletools | 8.57 | cpe:2.3:a:oracle:peoplesoft_enterprise_pt_peopletools:8.57:*:*:*:*:*:*:* |
| oracle | peoplesoft_enterprise_pt_peopletools | 8.58 | cpe:2.3:a:oracle:peoplesoft_enterprise_pt_peopletools:8.58:*:*:*:*:*:*:* |
| oracle | primavera_gateway | >= 16.2.0, <= 16.2.11 | cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* |
| oracle | primavera_gateway | >= 17.12.0, <= 17.12.6 | cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* |
| oracle | real-time_decisions_solutions | 3.2.0.0 | cpe:2.3:a:oracle:real-time_decisions_solutions:3.2.0.0:*:*:*:*:*:*:* |
| oracle | retail_advanced_inventory_planning | 14.1 | cpe:2.3:a:oracle:retail_advanced_inventory_planning:14.1:*:*:*:*:*:*:* |
| oracle | retail_back_office | 14.1 | cpe:2.3:a:oracle:retail_back_office:14.1:*:*:*:*:*:*:* |