<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T03:17:25.807839+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:9114</id>
    <title>ALSA-2025:9114 — Important: apache-commons-beanutils security update</title>
    <updated>2026-10-03T03:17:25.974423+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: apache-commons-beanutils</p>
<p>The Apache Commons BeanUtils library provides utility methods for accessing and modifying properties of arbitrary JavaBeans.</p>
<p>Security Fix(es):</p>
<p>* commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default (CVE-2025-48734)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:9114"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-06231</id>
    <title>bdu:2025-06231</title>
    <updated>2026-10-03T03:17:25.974534+00:00</updated>
    <content>bdu:2025-06231</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-06231"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0604</id>
    <title>certfr-2025-avi-0604 — De multiples vulnérabilités ont été découvertes dans Oracle Weblogic. Certaines d'entre elles permettent à un attaquant…</title>
    <updated>2026-10-03T03:17:25.974558+00:00</updated>
    <content>certfr-2025-avi-0604</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0604"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-cd91859</id>
    <title>CLEANSTART-2026-CD91859 — Security fix for CVE-2025-48734 applied in: apache-hive 4.0.0-r0, apache-hive 4.2.0-r1, cassandra-reaper-fips 3.6.1-r3,…</title>
    <updated>2026-10-03T03:17:25.974592+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: apache-hive, CleanStart: cassandra-reaper-fips, CleanStart: stargate, CleanStart: strimzi-kafka-operator</p>
<p>CVE-2025-48734 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-cd91859"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-307087</id>
    <title>EUVD-2026-307087</title>
    <updated>2026-10-03T03:17:25.974651+00:00</updated>
    <content>EUVD-2026-307087</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-307087"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-48734</id>
    <title>fkie_cve-2025-48734</title>
    <updated>2026-10-03T03:17:25.974675+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Improper Access Control vulnerability in Apache Commons.</p>
<p>A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default.</p>
<p>Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty().
Starting in versions 1.11.0 and 2.0.0-M2 a special BeanIntrospector suppresses the “declaredClass” property. Note that this new BeanIntrospector is enabled by default, but you can disable it to regain the old behavior; see section 2.5 of the user's guide and the unit tests.</p>
<p>This issue affects Apache Commons BeanUtils 1.x before 1.11.0, and 2.x before 2.0.0-M2.Users of the artifact commons-beanutils:commons-beanutils</p>
<p>1.x are recommended to upgrade to version 1.11.0, which fixes the issue.</p>
<p>Users of the ar…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-48734"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wxr5-93ph-8wr9</id>
    <title>GHSA-wxr5-93ph-8wr9 — Apache Commons Improper Access Control vulnerability</title>
    <updated>2026-10-03T03:17:25.974771+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: commons-beanutils:commons-beanutils, Maven: org.apache.commons:commons-beanutils2</p>
<p>Improper Access Control vulnerability in Apache Commons.</p>
<p>A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default.</p>
<p>Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty().
Starting in versions 1.11.0 and 2.0.0-M2 a special BeanIntrospector suppresses the “declaredClass” property. Note that this new BeanIntrospector is enabled by default, but you can disable it to regain the old behavior; see section 2.5 of the user's guide and the unit tests.</p>
<p>This issue affects Apache Commons BeanUtils 1.x before 1.11.0, and 2.x before 2.0.0-M2.Users of the artifact commons-beanutils:commons-beanutils</p>
<p>1.x are recommended to upgrade to version 1.11.0, which fixes the issue.</p>
<p>Users of the ar…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wxr5-93ph-8wr9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0022</id>
    <title>NCSC-2026-0022 — Kwetsbaarheden verholpen in Oracle Communications producten</title>
    <updated>2026-10-03T03:17:25.974855+00:00</updated>
    <content>NCSC-2026-0022</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0022"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1715</id>
    <title>OESA-2025-1715 — apache-commons-beanutils security update</title>
    <updated>2026-10-03T03:17:25.974977+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: apache-commons-beanutils, openEuler:22.03-LTS-SP4: apache-commons-beanutils, openEuler:24.03-LTS: apache-commons-beanutils, openEuler:24.03-LTS-SP1: apache-commons-beanutils, openEuler:20.03-LTS-SP4: apache-commons-beanutils</p>
<p>The scope of this package is to create a package of Java utility methods for accessing and modifying the properties of arbitrary JavaBeans.  No dependencies outside of the JDK are required, so the use of this package is very lightweight.

Security Fix(es):</p>
<p>A vulnerability, which was classified as critical, was found in Apache Commons BeanUtils up to 1.10.x/2.0.0-/1.CWE is classifying the issue as CWE-284. The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.This is going to have an impact on confidentiality, integrity, and availability.Upgrading to version 1.11.0 or 2.0.0-M2 eliminates this vulnerability.(CVE-2025-48734)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1715"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15175-1</id>
    <title>openSUSE-SU-2025:15175-1 — apache-commons-beanutils-1.11.0-1.1 on GA media</title>
    <updated>2026-10-03T03:17:25.975037+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>apache-commons-beanutils-1.11.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15175-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:10452</id>
    <title>RHSA-2025:10452 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 8.0.8 Security update</title>
    <updated>2026-10-03T03:17:25.975074+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>org.jboss.eap:wildfly-ejb3: Improper Deserialization in JBoss Marshalling Allows Remote Code Execution org.jboss.hal-hal-parent: Stored Cross-Site Scripting (XSS) in JBoss EAP Management Console org.apache.cxf: Apache CXF: Denial of Service vulnerability with temporary files base-x: base-x homograph attack allows Unicode lookalike characters to bypass validation. commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:10452"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:02056-1</id>
    <title>SUSE-SU-2025:02056-1 — Security update for apache-commons-beanutils</title>
    <updated>2026-10-03T03:17:25.975120+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for apache-commons-beanutils</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:02056-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-48734</id>
    <title>UBUNTU-CVE-2025-48734</title>
    <updated>2026-10-03T03:17:25.975148+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: commons-beanutils, Ubuntu:Pro:18.04:LTS: commons-beanutils, Ubuntu:Pro:20.04:LTS: commons-beanutils, Ubuntu:22.04:LTS: commons-beanutils, Ubuntu:Pro:24.04:LTS: commons-beanutils</p>
<p>Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Starting in versions 1.11.0 and 2.0.0-M2 a special BeanIntrospector suppresses the “declaredClass” property. Note that this new BeanIntrospector is enabled by default, but you can disable it to regain the old behavior; see section 2.5 of the user's guide and the unit tests. This issue affects Apache Commons BeanUtils 1.x before 1.11.0, and 2.x before 2.0.0-M2.Users of the artifact commons-beanutils:commons-beanutils  1.x are recommended to upgrade to version 1.11.0, which fixes the issue. Users of the artifact org.a…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-48734"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1169</id>
    <title>WID-SEC-W-2025-1169 — Apache Commons BeanUtils: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-03T03:17:25.975256+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Apache Commons BeanUtils ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1169"/>
  </entry>
</feed>
