{"id":"USN-8322-2","summary":"commons-beanutils regression","details":"USN-8322-1 fixed a vulnerability in Apache Commons BeanUtils. It was\ndiscovered that for Ubuntu 18.04 LTS, during the update preparation\nphase, a previous fix for CVE-2014-0114 and CVE-2019-10086 was\nincorrectly dropped. This update reintroduces the fix for\nCVE-2014-0114 and CVE-2019-10086.\n\nWe apologize for the inconvenience.\n\nOriginal advisory details:\n\n It was discovered that Apache Commons BeanUtils incorrectly allowed\n access to the declaredClass property of Java enum objects when handling\n externally supplied property paths. An attacker could possibly use this\n issue to execute arbitrary code.","modified":"2026-07-23T21:13:49.067399314Z","published":"2026-07-23T10:39:20Z","upstream":["CVE-2014-0114","CVE-2019-10086","UBUNTU-CVE-2014-0114","UBUNTU-CVE-2019-10086"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8322-2"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-0114"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2019-10086"},{"type":"REPORT","url":"https://launchpad.net/bugs/2161582"}],"affected":[{"package":{"name":"commons-beanutils","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/commons-beanutils?arch=source&distro=esm-apps-legacy%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.9.2-3ubuntu0.1~esm2"}]}],"versions":["1.9.2-1","1.9.2-2","1.9.2-3","1.9.2-3ubuntu0.1~esm1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro","binaries":[{"binary_name":"libcommons-beanutils-java","binary_version":"1.9.2-3ubuntu0.1~esm2"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:16.04:LTS","cves":[{"severity":[{"type":"Ubuntu","score":"medium"}],"id":"CVE-2014-0114"},{"id":"CVE-2019-10086","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},{"type":"Ubuntu","score":"medium"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8322-2.json"}}],"schema_version":"1.7.5"}