<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:16:37 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:9114 — Important: apache-commons-beanutils security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:9114</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: apache-commons-beanutils&lt;/p&gt;
&lt;p&gt;The Apache Commons BeanUtils library provides utility methods for accessing and modifying properties of arbitrary JavaBeans.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum&amp;#39;s declaredClass property by default (CVE-2025-48734)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: apache-commons-beanutils&lt;/p&gt;
&lt;p&gt;The Apache Commons BeanUtils library provides utility methods for accessing and modifying properties of arbitrary JavaBeans.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum&amp;#39;s declaredClass property by default (CVE-2025-48734)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:9114</guid>
    </item>
    <item>
      <title>bdu:2025-06231</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-06231</link>
      <description>bdu:2025-06231</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-06231</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0604 — De multiples vulnérabilités ont été découvertes dans Oracle Weblogic. Certaines d'entre elles permettent à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0604</link>
      <description>certfr-2025-avi-0604</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0604</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-CD91859 — Security fix for CVE-2025-48734 applied in: apache-hive 4.0.0-r0, apache-hive 4.2.0-r1, cassandra-reaper-fips 3.6.1-r3,…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-cd91859</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-hive, CleanStart: cassandra-reaper-fips, CleanStart: stargate, CleanStart: strimzi-kafka-operator&lt;/p&gt;
&lt;p&gt;CVE-2025-48734 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-hive, CleanStart: cassandra-reaper-fips, CleanStart: stargate, CleanStart: strimzi-kafka-operator&lt;/p&gt;
&lt;p&gt;CVE-2025-48734 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-cd91859</guid>
    </item>
    <item>
      <title>EUVD-2026-307087</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-307087</link>
      <description>EUVD-2026-307087</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-307087</guid>
    </item>
    <item>
      <title>fkie_cve-2025-48734</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-48734</link>
      <description>&lt;p&gt;Improper Access Control vulnerability in Apache Commons.&lt;/p&gt;
&lt;p&gt;A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default.&lt;/p&gt;
&lt;p&gt;Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty().
Starting in versions 1.11.0 and 2.0.0-M2 a special BeanIntrospector suppresses the “declaredClass” property. Note that this new BeanIntrospector is enabled by default, but you can disable it to regain the old behavior; see section 2.5 of the user&amp;#39;s guide and the unit tests.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Commons BeanUtils 1.x before 1.11.0, and 2.x before 2.0.0-M2.Users of the artifact commons-beanutils:commons-beanutils&lt;/p&gt;
&lt;p&gt;1.x are recommended to upgrade to version 1.11.0, which fixes the issue.&lt;/p&gt;
&lt;p&gt;Users of the ar…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper Access Control vulnerability in Apache Commons.&lt;/p&gt;
&lt;p&gt;A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default.&lt;/p&gt;
&lt;p&gt;Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty().
Starting in versions 1.11.0 and 2.0.0-M2 a special BeanIntrospector suppresses the “declaredClass” property. Note that this new BeanIntrospector is enabled by default, but you can disable it to regain the old behavior; see section 2.5 of the user&amp;#39;s guide and the unit tests.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Commons BeanUtils 1.x before 1.11.0, and 2.x before 2.0.0-M2.Users of the artifact commons-beanutils:commons-beanutils&lt;/p&gt;
&lt;p&gt;1.x are recommended to upgrade to version 1.11.0, which fixes the issue.&lt;/p&gt;
&lt;p&gt;Users of the ar…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-48734</guid>
    </item>
    <item>
      <title>GHSA-wxr5-93ph-8wr9 — Apache Commons Improper Access Control vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wxr5-93ph-8wr9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: commons-beanutils:commons-beanutils, Maven: org.apache.commons:commons-beanutils2&lt;/p&gt;
&lt;p&gt;Improper Access Control vulnerability in Apache Commons.&lt;/p&gt;
&lt;p&gt;A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default.&lt;/p&gt;
&lt;p&gt;Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty().
Starting in versions 1.11.0 and 2.0.0-M2 a special BeanIntrospector suppresses the “declaredClass” property. Note that this new BeanIntrospector is enabled by default, but you can disable it to regain the old behavior; see section 2.5 of the user&amp;#39;s guide and the unit tests.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Commons BeanUtils 1.x before 1.11.0, and 2.x before 2.0.0-M2.Users of the artifact commons-beanutils:commons-beanutils&lt;/p&gt;
&lt;p&gt;1.x are recommended to upgrade to version 1.11.0, which fixes the issue.&lt;/p&gt;
&lt;p&gt;Users of the ar…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: commons-beanutils:commons-beanutils, Maven: org.apache.commons:commons-beanutils2&lt;/p&gt;
&lt;p&gt;Improper Access Control vulnerability in Apache Commons.&lt;/p&gt;
&lt;p&gt;A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default.&lt;/p&gt;
&lt;p&gt;Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty().
Starting in versions 1.11.0 and 2.0.0-M2 a special BeanIntrospector suppresses the “declaredClass” property. Note that this new BeanIntrospector is enabled by default, but you can disable it to regain the old behavior; see section 2.5 of the user&amp;#39;s guide and the unit tests.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Commons BeanUtils 1.x before 1.11.0, and 2.x before 2.0.0-M2.Users of the artifact commons-beanutils:commons-beanutils&lt;/p&gt;
&lt;p&gt;1.x are recommended to upgrade to version 1.11.0, which fixes the issue.&lt;/p&gt;
&lt;p&gt;Users of the ar…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wxr5-93ph-8wr9</guid>
    </item>
    <item>
      <title>NCSC-2026-0022 — Kwetsbaarheden verholpen in Oracle Communications producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0022</link>
      <description>NCSC-2026-0022</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0022</guid>
    </item>
    <item>
      <title>OESA-2025-1715 — apache-commons-beanutils security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1715</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: apache-commons-beanutils, openEuler:22.03-LTS-SP4: apache-commons-beanutils, openEuler:24.03-LTS: apache-commons-beanutils, openEuler:24.03-LTS-SP1: apache-commons-beanutils, openEuler:20.03-LTS-SP4: apache-commons-beanutils&lt;/p&gt;
&lt;p&gt;The scope of this package is to create a package of Java utility methods for accessing and modifying the properties of arbitrary JavaBeans.  No dependencies outside of the JDK are required, so the use of this package is very lightweight.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability, which was classified as critical, was found in Apache Commons BeanUtils up to 1.10.x/2.0.0-/1.CWE is classifying the issue as CWE-284. The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.This is going to have an impact on confidentiality, integrity, and availability.Upgrading to version 1.11.0 or 2.0.0-M2 eliminates this vulnerability.(CVE-2025-48734)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: apache-commons-beanutils, openEuler:22.03-LTS-SP4: apache-commons-beanutils, openEuler:24.03-LTS: apache-commons-beanutils, openEuler:24.03-LTS-SP1: apache-commons-beanutils, openEuler:20.03-LTS-SP4: apache-commons-beanutils&lt;/p&gt;
&lt;p&gt;The scope of this package is to create a package of Java utility methods for accessing and modifying the properties of arbitrary JavaBeans.  No dependencies outside of the JDK are required, so the use of this package is very lightweight.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability, which was classified as critical, was found in Apache Commons BeanUtils up to 1.10.x/2.0.0-/1.CWE is classifying the issue as CWE-284. The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.This is going to have an impact on confidentiality, integrity, and availability.Upgrading to version 1.11.0 or 2.0.0-M2 eliminates this vulnerability.(CVE-2025-48734)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1715</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15175-1 — apache-commons-beanutils-1.11.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15175-1</link>
      <description>&lt;p&gt;apache-commons-beanutils-1.11.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;apache-commons-beanutils-1.11.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15175-1</guid>
    </item>
    <item>
      <title>RHSA-2025:10452 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 8.0.8 Security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:10452</link>
      <description>&lt;p&gt;org.jboss.eap:wildfly-ejb3: Improper Deserialization in JBoss Marshalling Allows Remote Code Execution org.jboss.hal-hal-parent: Stored Cross-Site Scripting (XSS) in JBoss EAP Management Console org.apache.cxf: Apache CXF: Denial of Service vulnerability with temporary files base-x: base-x homograph attack allows Unicode lookalike characters to bypass validation. commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum&amp;#39;s declaredClass property by default&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;org.jboss.eap:wildfly-ejb3: Improper Deserialization in JBoss Marshalling Allows Remote Code Execution org.jboss.hal-hal-parent: Stored Cross-Site Scripting (XSS) in JBoss EAP Management Console org.apache.cxf: Apache CXF: Denial of Service vulnerability with temporary files base-x: base-x homograph attack allows Unicode lookalike characters to bypass validation. commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum&amp;#39;s declaredClass property by default&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:10452</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:02056-1 — Security update for apache-commons-beanutils</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:02056-1</link>
      <description>&lt;p&gt;Security update for apache-commons-beanutils&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for apache-commons-beanutils&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:02056-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-48734</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-48734</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: commons-beanutils, Ubuntu:Pro:18.04:LTS: commons-beanutils, Ubuntu:Pro:20.04:LTS: commons-beanutils, Ubuntu:22.04:LTS: commons-beanutils, Ubuntu:Pro:24.04:LTS: commons-beanutils&lt;/p&gt;
&lt;p&gt;Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Starting in versions 1.11.0 and 2.0.0-M2 a special BeanIntrospector suppresses the “declaredClass” property. Note that this new BeanIntrospector is enabled by default, but you can disable it to regain the old behavior; see section 2.5 of the user&amp;#39;s guide and the unit tests. This issue affects Apache Commons BeanUtils 1.x before 1.11.0, and 2.x before 2.0.0-M2.Users of the artifact commons-beanutils:commons-beanutils  1.x are recommended to upgrade to version 1.11.0, which fixes the issue. Users of the artifact org.a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: commons-beanutils, Ubuntu:Pro:18.04:LTS: commons-beanutils, Ubuntu:Pro:20.04:LTS: commons-beanutils, Ubuntu:22.04:LTS: commons-beanutils, Ubuntu:Pro:24.04:LTS: commons-beanutils&lt;/p&gt;
&lt;p&gt;Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Starting in versions 1.11.0 and 2.0.0-M2 a special BeanIntrospector suppresses the “declaredClass” property. Note that this new BeanIntrospector is enabled by default, but you can disable it to regain the old behavior; see section 2.5 of the user&amp;#39;s guide and the unit tests. This issue affects Apache Commons BeanUtils 1.x before 1.11.0, and 2.x before 2.0.0-M2.Users of the artifact commons-beanutils:commons-beanutils  1.x are recommended to upgrade to version 1.11.0, which fixes the issue. Users of the artifact org.a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-48734</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1169 — Apache Commons BeanUtils: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1169</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Apache Commons BeanUtils ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Apache Commons BeanUtils ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1169</guid>
    </item>
  </channel>
</rss>
