CVE-2025-48734

high
Published 2025-06-16 Β· Modified 2025-07-02
CVSS v3
β€”
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
8.0

Description

Important: apache-commons-beanutils security update

Predictions

Exploit likelihood
30%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default Red Hat statement This vulnerability is rated as important severity because a flaw exists in Apache Commons BeanUtils, where PropertyUtilsBean and BeanUtilsBean allow uncontrolled access to the declaredClass property of Java enum objects. Applications that…

Description

commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default

Red Hat statement

This vulnerability is rated as important severity because a flaw exists in Apache Commons BeanUtils, where PropertyUtilsBean and BeanUtilsBean allow uncontrolled access to the declaredClass property of Java enum objects. Applications that pass untrusted property paths directly to getProperty() or getNestedProperty() methods are at risk, as attackers can exploit this behavior to retrieve the ClassLoader instance and execute arbitrary code in the context of the affected application. This issue leads to compromise of confidentiality, integrity, and availability.

CVSS v3: 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Cryostat 4 on RHEL 9cryostat/cryostat-agent-init-rhel9:0.5.1-1RHSA-2025:82652025-06-05T00:00:00Z
Cryostat 4 on RHEL 9cryostat/cryostat-db-rhel9:4.0.1-4RHSA-2025:82652025-06-05T00:00:00Z
Cryostat 4 on RHEL 9cryostat/cryostat-grafana-dashboard-rhel9:4.0.1-3RHSA-2025:82652025-06-05T00:00:00Z
Cryostat 4 on RHEL 9cryostat/cryostat-openshift-console-plugin-rhel9:4.0.1-2RHSA-2025:82652025-06-05T00:00:00Z
Cryostat 4 on RHEL 9cryostat/cryostat-operator-bundle:4.0.1-1RHSA-2025:82652025-06-05T00:00:00Z
Cryostat 4 on RHEL 9cryostat/cryostat-ose-oauth-proxy-rhel9:4.0.1-4RHSA-2025:82652025-06-05T00:00:00Z
Cryostat 4 on RHEL 9cryostat/cryostat-reports-rhel9:4.0.1-2RHSA-2025:82652025-06-05T00:00:00Z
Cryostat 4 on RHEL 9cryostat/cryostat-rhel9:4.0.1-2RHSA-2025:82652025-06-05T00:00:00Z
Cryostat 4 on RHEL 9cryostat/cryostat-rhel9-operator:4.0.1-4RHSA-2025:82652025-06-05T00:00:00Z
Cryostat 4 on RHEL 9cryostat/cryostat-storage-rhel9:4.0.1-4RHSA-2025:82652025-06-05T00:00:00Z
Cryostat 4 on RHEL 9cryostat/jfr-datasource-rhel9:4.0.1-2RHSA-2025:82652025-06-05T00:00:00Z
OCP-Tools-4.12-RHEL-8jenkins-0:2.516.2.1756902453-3.el8RHSA-2025:158132025-09-15T00:00:00Z
OCP-Tools-4.12-RHEL-8jenkins-2-plugins-0:4.12.1756902839-1.el8RHSA-2025:158132025-09-15T00:00:00Z
OCP-Tools-4.13-RHEL-8jenkins-0:2.516.2.1756902120-3.el8RHSA-2025:158152025-09-15T00:00:00Z
OCP-Tools-4.13-RHEL-8jenkins-2-plugins-0:4.13.1756901992-1.el8RHSA-2025:158152025-09-15T00:00:00Z
OCP-Tools-4.14-RHEL-8jenkins-0:2.516.2.1757087588-3.el8RHSA-2025:158162025-09-15T00:00:00Z
OCP-Tools-4.14-RHEL-8jenkins-2-plugins-0:4.14.1757087858-1.el8RHSA-2025:158162025-09-15T00:00:00Z
OCP-Tools-4.15-RHEL-8jenkins-0:2.516.2.1756738247-3.el8RHSA-2025:158172025-09-15T00:00:00Z
OCP-Tools-4.15-RHEL-8jenkins-2-plugins-0:4.15.1756735456-1.el8RHSA-2025:158172025-09-15T00:00:00Z
OCP-Tools-4.16-RHEL-9jenkins-0:2.516.2.1756733848-3.el9RHSA-2025:158112025-09-15T00:00:00Z
OCP-Tools-4.16-RHEL-9jenkins-2-plugins-0:4.16.1756734507-1.el9RHSA-2025:158112025-09-15T00:00:00Z
OCP-Tools-4.17-RHEL-9jenkins-0:2.516.2.1756732303-3.el9RHSA-2025:158142025-09-15T00:00:00Z
OCP-Tools-4.17-RHEL-9jenkins-2-plugins-0:4.17.1756732064-1.el9RHSA-2025:158142025-09-15T00:00:00Z
OCP-Tools-4.18-RHEL-9jenkins-0:2.516.2.1756731431-3.el9RHSA-2025:158102025-09-15T00:00:00Z
OCP-Tools-4.18-RHEL-9jenkins-2-plugins-0:4.18.1756731677-1.el9RHSA-2025:158102025-09-15T00:00:00Z
OCP-Tools-4.19-RHEL-9jenkins-0:2.516.2.1756903379-3.el9RHSA-2025:158122025-09-15T00:00:00Z
OCP-Tools-4.19-RHEL-9jenkins-2-plugins-0:4.19.1756901647-1.el9RHSA-2025:158122025-09-15T00:00:00Z
Red Hat AMQ Broker 7.12.5commons-beanutilsRHSA-2025:164092025-09-22T00:00:00Z
Red Hat AMQ Broker 7.13.1commons-beanutilsRHSA-2025:132742025-08-06T00:00:00Z
Red Hat build of Apache Camel 4.10.3 for Spring Boot 3.4.7commons-beanutilsRHSA-2025:96972025-06-25T00:00:00Z
Red Hat Build of Apache Camel 4.10 for Quarkus 3.20quarkus-camel-bomRHSA-2025:89192025-06-11T00:00:00Z
Red Hat Build of Apache Camel 4.10 for Quarkus 3.20quarkus-cxf-bomRHSA-2025:89192025-06-11T00:00:00Z
Red Hat Enterprise Linux 10apache-commons-beanutils-0:1.9.4-21.el10_0RHSA-2025:91662025-06-17T00:00:00Z
Red Hat Enterprise Linux 7 Extended Lifecycle Supportapache-commons-beanutils-0:1.8.3-15.el7_9.1RHSA-2025:108142025-07-10T00:00:00Z
Red Hat Enterprise Linux 8javapackages-tools:201801-8100020250616113255.88f2bc72RHSA-2025:93182025-06-23T00:00:00Z
Red Hat Enterprise Linux 9apache-commons-beanutils-0:1.9.4-10.el9_6RHSA-2025:91142025-06-16T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportapache-commons-beanutils-0:1.9.4-9.el9_4.1RHSA-2025:96962025-06-25T00:00:00Z
Red Hat JBoss Enterprise Application Platform 7commons-beanutilsRHSA-2025:34672025-04-01T00:00:00Z
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7eap7-apache-commons-beanutils-0:1.11.0-1.redhat_00001.1.ep7.el7RHSA-2025:166682025-09-25T00:00:00Z
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7eap7-hibernate-validator-0:5.3.6-1.SP1_redhat_00001.1.ep7.el7RHSA-2025:166682025-09-25T00:00:00Z
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7eap7-hornetq-0:2.4.11-1.Final_redhat_00001.1.ep7.el7RHSA-2025:166682025-09-25T00:00:00Z
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7eap7-undertow-0:1.4.18-17.SP15_redhat_00001.1.ep7.el7RHSA-2025:166682025-09-25T00:00:00Z
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7eap7-wildfly-0:7.1.12-2.GA_redhat_00002.1.ep7.el7RHSA-2025:166682025-09-25T00:00:00Z
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7eap7-apache-commons-beanutils-0:1.11.0-1.redhat_00001.1.el7eapRHSA-2025:166672025-09-25T00:00:00Z
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7eap7-hornetq-0:2.4.11-1.Final_redhat_00001.1.el7eapRHSA-2025:166672025-09-25T00:00:00Z
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7eap7-jboss-server-migration-0:1.7.2-19.Final_redhat_00020.1.el7eapRHSA-2025:166672025-09-25T00:00:00Z
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7eap7-undertow-0:2.0.41-5.SP6_redhat_00001.1.el7eapRHSA-2025:166672025-09-25T00:00:00Z
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7eap7-wildfly-0:7.3.15-5.GA_redhat_00003.1.el7eapRHSA-2025:166672025-09-25T00:00:00Z
Red Hat JBoss Enterprise Application Platform 7.4.22RHSA-2025:91172025-06-16T00:00:00Z
Red Hat JBoss Enterprise Application Platform 7.4.23RHSA-2025:109312025-07-14T00:00:00Z
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-activemq-artemis-0:2.16.0-21.redhat_00055.1.el8eapRHSA-2025:109252025-07-14T00:00:00Z
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-apache-cxf-0:3.5.10-1.redhat_00001.1.el8eapRHSA-2025:109252025-07-14T00:00:00Z
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-artemis-native-1:1.0.2-5.redhat_00004.1.el8eapRHSA-2025:109252025-07-14T00:00:00Z
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-elytron-web-0:1.9.6-1.Final_redhat_00001.1.el8eapRHSA-2025:109252025-07-14T00:00:00Z
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-glassfish-jsf-0:2.3.14-9.SP10_redhat_00001.1.el8eapRHSA-2025:109252025-07-14T00:00:00Z
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-hal-console-0:3.3.27-1.Final_redhat_00001.1.el8eapRHSA-2025:109252025-07-14T00:00:00Z
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-hibernate-validator-0:6.0.23-3.SP2_redhat_00001.1.el8eapRHSA-2025:109252025-07-14T00:00:00Z
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-ironjacamar-0:1.5.21-1.Final_redhat_00001.1.el8eapRHSA-2025:109252025-07-14T00:00:00Z
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-jboss-server-migration-0:1.10.0-42.Final_redhat_00042.1.el8eapRHSA-2025:109252025-07-14T00:00:00Z
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-jbossws-cxf-0:5.4.15-1.Final_redhat_00001.1.el8eapRHSA-2025:109252025-07-14T00:00:00Z

Package state

ProductPackageState
A-MQ Clients 2commons-beanutilsWill not fix
A-MQ Clients 2commons-beanutils-coreWill not fix
Red Hat AMQ Clientscommons-beanutilsWill not fix
Red Hat Ansible Automation Platform 2commons-beanutilsNot affected
Red Hat build of Apache Camel - HawtIO 4commons-beanutilsNot affected
Red Hat build of Apicurio Registry 2commons-beanutilsAffected
Red Hat build of Apicurio Registry 3commons-beanutilsAffected
Red Hat build of Debezium 2commons-beanutilsWill not fix
Red Hat build of Debezium 2commons-beanutils-coreWill not fix
Red Hat build of Debezium 3commons-beanutilsWill not fix
Red Hat build of Debezium 3commons-beanutils-coreWill not fix
Red Hat build of OptaPlanner 8commons-beanutilsWill not fix
Red Hat Data Grid 8commons-beanutilsWill not fix
Red Hat Data Grid 8commons-beanutils-coreWill not fix
Red Hat Enterprise Linux 6jakarta-commons-beanutilsOut of support scope
Red Hat Enterprise Linux 6qpid-cppOut of support scope
Red Hat Enterprise Linux 6qpid-qmfOut of support scope
Red Hat Enterprise Linux 6sat4jOut of support scope
Red Hat Enterprise Linux 7xbeanOut of support scope
Red Hat Enterprise Linux 9jmcNot affected
Red Hat Enterprise Linux 9xbeanNot affected
Red Hat Fuse 7commons-beanutilsWill not fix
Red Hat Fuse 7commons-beanutils-coreWill not fix
Red Hat Integration Camel K 1commons-beanutilsWill not fix
Red Hat Integration Camel K 1commons-beanutils-coreWill not fix
Red Hat JBoss Enterprise Application Platform Expansion Packcommons-beanutilsNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packorg.jboss.eap-jboss-eap-xpNot affected
Red Hat JBoss Web Server 5commons-beanutilsNot affected
Red Hat JBoss Web Server 6commons-beanutilsNot affected
Red Hat Process Automation 7commons-beanutilsAffected
Red Hat Process Automation 7commons-beanutils-coreAffected
Red Hat Satellite 6commons-beanutilsNot affected
Red Hat Single Sign-On 7commons-beanutilsNot affected
streams for Apache Kafkacommons-beanutilsAffected
streams for Apache Kafkacommons-beanutils-coreAffected

Apply commands

bash fix
Apply RHSA-2025:8265 for Cryostat 4 on RHEL 9
yum update -y cryostat/cryostat-agent-init-rhel9:0
# or:
dnf upgrade -y cryostat/cryostat-agent-init-rhel9:0

Affected

VendorProductVersion
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat build of Apache Camel - HawtIO 4Not affected
redhatRed Hat build of Apicurio Registry 2Affected
redhatRed Hat build of Apicurio Registry 3Affected
redhatRed Hat Enterprise Linux 9Not affected
redhatRed Hat Enterprise Linux 9Not affected
redhatRed Hat JBoss Enterprise Application Platform Expansion PackNot affected
redhatRed Hat JBoss Enterprise Application Platform Expansion PackNot affected
redhatRed Hat JBoss Web Server 5Not affected
redhatRed Hat JBoss Web Server 6Not affected
redhatRed Hat Process Automation 7Affected
redhatRed Hat Process Automation 7Affected
redhatRed Hat Satellite 6Not affected
redhatRed Hat Single Sign-On 7Not affected
redhatstreams for Apache KafkaAffected
redhatstreams for Apache KafkaAffected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
9 Fixed apache-commons-beanutils-1.9.4-10.el9_6.noarch.rpm
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 1.10.1-1.1
sid Fixed 1.10.1-1.1
forky Fixed 1.10.1-1.1
bullseye Fixed 1.9.4-1+deb11u1
bookworm Fixed 1.9.4-1+deb12u1
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”
rockylinux Rocky Linux Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”

Package impact

EcosystemPackageVulnerableFixed
java Mavencommons-beanutils:commons-beanutils>=1.0,<1.11.01.11.0
java Mavenorg.apache.commons:commons-beanutils2>=2.0.0-M1,<2.0.0-M22.0.0-M2

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.