ID:8517 - Exploit for Unsafe reflection in Apache Commons BeanUtils - CVE-2014-0114

 
Main Vulnerability Database Exploits ID:8517 - Exploit for Unsafe reflection in Apache Commons BeanUtils - CVE-2014-0114

ID:8517 - Exploit for Unsafe reflection in Apache Commons BeanUtils - CVE-2014-0114

Published: October 22, 2022


Vulnerability identifier: #VU65653
Vulnerability risk: Medium
CVE-ID: CVE-2014-0114
CWE-ID: CWE-470
Exploitation vector: Remote access
Vulnerable software:
Apache Commons BeanUtils

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to Apache Commons BeanUtils does not suppress the class property. A remote unauthenticated attacker can manipulate the ClassLoader and execute arbitrary code via the class parameter


Remediation

Install updates from vendor's website.