RHSA-2025:9318HighCVSS 8.8

Red Hat Security Advisory: javapackages-tools:201801 security update

Published
June 23, 2025
Last Modified
October 9, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2019-10086 — apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default CVE-2025-48734 — commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default

🎯 Affected products200

  • Red Hat Enterprise Linux CRB (v. 8)
  • ant-0:1.10.5-1.module+el8.10.0+23274+27840b45.noarch (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • ant-0:1.10.5-1.module+el8.10.0+23274+27840b45.src (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • ant-antlr-0:1.10.5-1.module+el8.10.0+23274+27840b45.noarch (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • ant-apache-bcel-0:1.10.5-1.module+el8.10.0+23274+27840b45.noarch (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • ant-apache-bsf-0:1.10.5-1.module+el8.10.0+23274+27840b45.noarch (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • ant-apache-log4j-0:1.10.5-1.module+el8.10.0+23274+27840b45.noarch (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • ant-apache-oro-0:1.10.5-1.module+el8.10.0+23274+27840b45.noarch (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • ant-apache-regexp-0:1.10.5-1.module+el8.10.0+23274+27840b45.noarch (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • ant-apache-resolver-0:1.10.5-1.module+el8.10.0+23274+27840b45.noarch (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • ant-apache-xalan2-0:1.10.5-1.module+el8.10.0+23274+27840b45.noarch (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • ant-commons-logging-0:1.10.5-1.module+el8.10.0+23274+27840b45.noarch (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • ant-commons-net-0:1.10.5-1.module+el8.10.0+23274+27840b45.noarch (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • ant-contrib-0:1.0-0.32.b3.module+el8.10.0+23274+27840b45.noarch (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • ant-contrib-0:1.0-0.32.b3.module+el8.10.0+23274+27840b45.src (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • ant-contrib-javadoc-0:1.0-0.32.b3.module+el8.10.0+23274+27840b45.noarch (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • ant-javadoc-0:1.10.5-1.module+el8.10.0+23274+27840b45.noarch (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • ant-javamail-0:1.10.5-1.module+el8.10.0+23274+27840b45.noarch (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • ant-jdepend-0:1.10.5-1.module+el8.10.0+23274+27840b45.noarch (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • ant-jmf-0:1.10.5-1.module+el8.10.0+23274+27840b45.noarch (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • ant-jsch-0:1.10.5-1.module+el8.10.0+23274+27840b45.noarch (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • ant-junit-0:1.10.5-1.module+el8.10.0+23274+27840b45.noarch (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • ant-lib-0:1.10.5-1.module+el8.10.0+23274+27840b45.noarch (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • ant-manual-0:1.10.5-1.module+el8.10.0+23274+27840b45.noarch (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • ant-swing-0:1.10.5-1.module+el8.10.0+23274+27840b45.noarch (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • ant-testutil-0:1.10.5-1.module+el8.10.0+23274+27840b45.noarch (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • ant-xz-0:1.10.5-1.module+el8.10.0+23274+27840b45.noarch (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • antlr-0:2.7.7-56.module+el8.10.0+23274+27840b45.src (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • antlr-C++-0:2.7.7-56.module+el8.10.0+23274+27840b45.aarch64 (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • antlr-C++-0:2.7.7-56.module+el8.10.0+23274+27840b45.ppc64le (javapackages-tools:201801) as a component of Red Hat Enterprise Linux CRB (v. 8)
  • +170 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: There is no currently known mitigation for this flaw.

🔗 References (5)