<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:34:39 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:9318 — Important: javapackages-tools:201801 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:9318</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: ant, AlmaLinux:8: ant-antlr, AlmaLinux:8: ant-apache-bcel, AlmaLinux:8: ant-apache-bsf, AlmaLinux:8: ant-apache-log4j, AlmaLinux:8: ant-apache-oro, AlmaLinux:8: ant-apache-regexp, AlmaLinux:8: ant-apache-resolver, AlmaLinux:8: ant-apache-xalan2, AlmaLinux:8: ant-commons-logging and 500 more&lt;/p&gt;
&lt;p&gt;The javapackages-tools packages provide macros and scripts to support Java packaging.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default (CVE-2019-10086)
  * commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum&amp;#39;s declaredClass property by default (CVE-2025-48734)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: ant, AlmaLinux:8: ant-antlr, AlmaLinux:8: ant-apache-bcel, AlmaLinux:8: ant-apache-bsf, AlmaLinux:8: ant-apache-log4j, AlmaLinux:8: ant-apache-oro, AlmaLinux:8: ant-apache-regexp, AlmaLinux:8: ant-apache-resolver, AlmaLinux:8: ant-apache-xalan2, AlmaLinux:8: ant-commons-logging and 500 more&lt;/p&gt;
&lt;p&gt;The javapackages-tools packages provide macros and scripts to support Java packaging.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default (CVE-2019-10086)
  * commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum&amp;#39;s declaredClass property by default (CVE-2025-48734)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:9318</guid>
    </item>
    <item>
      <title>bdu:2020-01020</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-01020</link>
      <description>bdu:2020-01020</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-01020</guid>
    </item>
    <item>
      <title>certfr-2020-avi-433 — De multiples vulnérabilités ont été découvertes dans Oracle Database
Server. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-433</link>
      <description>certfr-2020-avi-433</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-433</guid>
    </item>
    <item>
      <title>cnvd-2019-42779</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2019-42779</link>
      <description>cnvd-2019-42779</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2019-42779</guid>
    </item>
    <item>
      <title>EUVD-2026-53346</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-53346</link>
      <description>EUVD-2026-53346</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-53346</guid>
    </item>
    <item>
      <title>fkie_cve-2019-10086</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-10086</link>
      <description>&lt;p&gt;In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-10086</guid>
    </item>
    <item>
      <title>GHSA-6phf-73q6-gh87 — Insecure Deserialization in Apache Commons Beanutils</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6phf-73q6-gh87</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: commons-beanutils:commons-beanutils&lt;/p&gt;
&lt;p&gt;In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: commons-beanutils:commons-beanutils&lt;/p&gt;
&lt;p&gt;In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6phf-73q6-gh87</guid>
    </item>
    <item>
      <title>gsd-2019-10086</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-10086</link>
      <description>gsd-2019-10086</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-10086</guid>
    </item>
    <item>
      <title>openSUSE-SU-2019:2058-1 — Security update for apache-commons-beanutils</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2019:2058-1</link>
      <description>&lt;p&gt;Security update for apache-commons-beanutils&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for apache-commons-beanutils&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2019:2058-1</guid>
    </item>
    <item>
      <title>RHBA-2020:0496 — Red Hat Bug Fix Advisory: Satellite 6.6.2 Async Bug Fix Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2020:0496</link>
      <description>&lt;p&gt;apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2020:0496</guid>
    </item>
    <item>
      <title>SUSE-SU-2019:2244-1 — Security update for apache-commons-beanutils</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2019:2244-1</link>
      <description>&lt;p&gt;Security update for apache-commons-beanutils&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for apache-commons-beanutils&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2019:2244-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2019-10086</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-10086</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: commons-beanutils, Ubuntu:Pro:16.04:LTS: commons-beanutils, Ubuntu:Pro:18.04:LTS: commons-beanutils&lt;/p&gt;
&lt;p&gt;In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: commons-beanutils, Ubuntu:Pro:16.04:LTS: commons-beanutils, Ubuntu:Pro:18.04:LTS: commons-beanutils&lt;/p&gt;
&lt;p&gt;In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-10086</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0770 — IBM DB2: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0770</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in IBM DB2 ausnutzen, um seine Privilegien zu erhöhen oder einen Denial of Service zu verursachen&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in IBM DB2 ausnutzen, um seine Privilegien zu erhöhen oder einen Denial of Service zu verursachen&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0770</guid>
    </item>
  </channel>
</rss>
