Loading
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
Use CWE-502, Apache vendor hub and Commons Beanutils product page to widen CVE-2019-10086 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2006-1547, CVE-2025-48734 and CVE-2014-0114 for nearby disclosures in the same product family.