Unsafe reflection in Apache Commons BeanUtils - CVE-2014-0114

 

Unsafe reflection in Apache Commons BeanUtils - CVE-2014-0114

Published: July 21, 2022 / Updated: October 22, 2022


Vulnerability identifier: #VU65653
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-0114
CWE-ID: CWE-470
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to Apache Commons BeanUtils does not suppress the class property. A remote unauthenticated attacker can manipulate the ClassLoader and execute arbitrary code via the class parameter


Affected software

Apache Commons BeanUtils
Jazz Foundation
Gentoo Linux
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
Ubuntu
IBM Tivoli System Automation Application Manager
IBM PureData System for Operational Analytics
IBM Tivoli Business Service Manager
Netcool Operations Insight
IBM Sterling B2B Integrator
HP SiteScope
IceWall Configuration Manager
Integration Designer
Multi-Enterprise Integration Gateway
B2B Advanced Communications
eDiscovery Manager
Oracle Insurance IFRS 17 Analyzer
dev-java/commons-beanutils
commons-beanutils (Ubuntu package)
apache-commons-beanutils
apache-commons-beanutils-javadoc
Fuse
Operational Decision Manager

How to mitigate CVE-2014-0114

Install updates from vendor's website.

Apache Commons BeanUtils - update to 1.9.2
IBM Tivoli Business Service Manager - update to 6.2.0.3.2
Multi-Enterprise Integration Gateway - update to 1.0.0.8
B2B Advanced Communications - update to 1.0.0.8
Netcool Operations Insight - update to 1.6.6
dev-java/commons-beanutils - update to 1.9.2
commons-beanutils (Ubuntu package) - update to 1.9.2-3ubuntu0.1~esm2
apache-commons-beanutils - update to 1.11.0-7.3.1
apache-commons-beanutils-javadoc - update to 1.11.0-7.3.1
eDiscovery Manager - update to 2.2.2.3.7
IBM Sterling B2B Integrator - addressed in versions 6.1.2.5, 6.2.0.1
Jazz Foundation - update to 7.0.2.0.29
Fuse - update to 7.1.0
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 33, 8.11.0.1 Interim fix 15, 8.11.1 Interim fix 4
HP SiteScope - addressed in versions 11.13, 11.24.271

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins