It was discovered that Apache Commons BeanUtils incorrectly allowed access to the declaredClass property of Java enum objects when handling externally supplied property paths. An attacker could possibly use this issue to execute arbitrary code.
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "1.9.4-1+deb11u1build0.22.04.1",
"binary_name": "libcommons-beanutils-java"
}
]
}"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8322-1.json"
{
"ecosystem": "Ubuntu:22.04:LTS",
"cves": [
{
"id": "CVE-2025-48734",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
}
]
}
{
"availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "1.9.1-1ubuntu0.1~esm2",
"binary_name": "libcommons-beanutils-java"
}
]
}"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8322-1.json"
{
"ecosystem": "Ubuntu:Pro:14.04:LTS",
"cves": [
{
"id": "CVE-2025-48734",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
}
]
}
{
"availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "1.9.2-3ubuntu0.1~esm1",
"binary_name": "libcommons-beanutils-java"
}
]
}"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8322-1.json"
{
"ecosystem": "Ubuntu:Pro:16.04:LTS",
"cves": [
{
"id": "CVE-2025-48734",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
}
]
}
{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "1.9.3-1ubuntu0.1~esm2",
"binary_name": "libcommons-beanutils-java"
}
]
}"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8322-1.json"
{
"ecosystem": "Ubuntu:Pro:18.04:LTS",
"cves": [
{
"id": "CVE-2025-48734",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
}
]
}
{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "1.9.4-1ubuntu0.20.04.1~esm1",
"binary_name": "libcommons-beanutils-java"
}
]
}"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8322-1.json"
{
"ecosystem": "Ubuntu:Pro:20.04:LTS",
"cves": [
{
"id": "CVE-2025-48734",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
}
]
}
{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "1.9.4-2ubuntu0.1~esm1",
"binary_name": "libcommons-beanutils-java"
}
]
}"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8322-1.json"
{
"ecosystem": "Ubuntu:Pro:24.04:LTS",
"cves": [
{
"id": "CVE-2025-48734",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
}
]
}