RHEL 8 : javapackages-tools:201801 (RHSA-2025:9318)

high Nessus Plugin ID 240247

Synopsis

The remote Red Hat host is missing one or more security updates for javapackages-tools:201801.

Description

The remote Redhat Enterprise Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2025:9318 advisory.

The javapackages-tools packages provide macros and scripts to support Java packaging.

Security Fix(es):

* apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default (CVE-2019-10086)

* commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default (CVE-2025-48734)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the RHEL javapackages-tools:201801 package based on the guidance in RHSA-2025:9318.

See Also

https://access.redhat.com/security/updates/classification/#important

https://bugzilla.redhat.com/show_bug.cgi?id=1767483

https://bugzilla.redhat.com/show_bug.cgi?id=2368956

http://www.nessus.org/u?2bb81c76

https://access.redhat.com/errata/RHSA-2025:9318

Plugin Details

Severity: High

ID: 240247

File Name: redhat-RHSA-2025-9318.nasl

Version: 1.2

Type: local

Agent: unix

Published: 6/23/2025

Updated: 6/23/2025

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

Vendor

Vendor Severity: Important

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2019-10086

CVSS v3

Risk Factor: High

Base Score: 7.3

Temporal Score: 6.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:redhat:enterprise_linux:8, p-cpe:/a:redhat:enterprise_linux:cglib, p-cpe:/a:redhat:enterprise_linux:javassist, p-cpe:/a:redhat:enterprise_linux:xerces-j2, p-cpe:/a:redhat:enterprise_linux:xerces-j2-demo, p-cpe:/a:redhat:enterprise_linux:jakarta-commons-httpclient, p-cpe:/a:redhat:enterprise_linux:xalan-j2, p-cpe:/a:redhat:enterprise_linux:xalan-j2-demo, p-cpe:/a:redhat:enterprise_linux:xalan-j2-javadoc, p-cpe:/a:redhat:enterprise_linux:xalan-j2-manual, p-cpe:/a:redhat:enterprise_linux:xalan-j2-xsltc, p-cpe:/a:redhat:enterprise_linux:plexus-archiver, p-cpe:/a:redhat:enterprise_linux:plexus-archiver-javadoc, p-cpe:/a:redhat:enterprise_linux:slf4j, p-cpe:/a:redhat:enterprise_linux:antlr, p-cpe:/a:redhat:enterprise_linux:bcel, p-cpe:/a:redhat:enterprise_linux:jaxen, p-cpe:/a:redhat:enterprise_linux:jdom, p-cpe:/a:redhat:enterprise_linux:aopalliance, p-cpe:/a:redhat:enterprise_linux:google-guice, p-cpe:/a:redhat:enterprise_linux:atinject, p-cpe:/a:redhat:enterprise_linux:httpcomponents-client, p-cpe:/a:redhat:enterprise_linux:httpcomponents-core, p-cpe:/a:redhat:enterprise_linux:httpcomponents-project, p-cpe:/a:redhat:enterprise_linux:jansi, p-cpe:/a:redhat:enterprise_linux:apache-commons-collections, p-cpe:/a:redhat:enterprise_linux:apache-commons-lang, p-cpe:/a:redhat:enterprise_linux:javassist-javadoc, p-cpe:/a:redhat:enterprise_linux:slf4j-jdk14, p-cpe:/a:redhat:enterprise_linux:velocity, p-cpe:/a:redhat:enterprise_linux:xml-commons-apis, p-cpe:/a:redhat:enterprise_linux:xml-commons-resolver, p-cpe:/a:redhat:enterprise_linux:apache-commons-beanutils, p-cpe:/a:redhat:enterprise_linux:apache-commons-cli, p-cpe:/a:redhat:enterprise_linux:jakarta-commons-httpclient-demo, p-cpe:/a:redhat:enterprise_linux:jakarta-commons-httpclient-javadoc, p-cpe:/a:redhat:enterprise_linux:jakarta-commons-httpclient-manual, p-cpe:/a:redhat:enterprise_linux:xerces-j2-javadoc, p-cpe:/a:redhat:enterprise_linux:jakarta-oro, p-cpe:/a:redhat:enterprise_linux:objectweb-asm, p-cpe:/a:redhat:enterprise_linux:apache-commons-beanutils-javadoc, p-cpe:/a:redhat:enterprise_linux:apache-commons-collections-javadoc, p-cpe:/a:redhat:enterprise_linux:apache-commons-collections-testframework, p-cpe:/a:redhat:enterprise_linux:objectweb-asm-javadoc, p-cpe:/a:redhat:enterprise_linux:bsf, p-cpe:/a:redhat:enterprise_linux:bsh, p-cpe:/a:redhat:enterprise_linux:isorelax, p-cpe:/a:redhat:enterprise_linux:jboss-parent, p-cpe:/a:redhat:enterprise_linux:regexp, p-cpe:/a:redhat:enterprise_linux:cal10n, p-cpe:/a:redhat:enterprise_linux:apache-commons-codec, p-cpe:/a:redhat:enterprise_linux:jcl-over-slf4j, p-cpe:/a:redhat:enterprise_linux:httpcomponents-client-javadoc, p-cpe:/a:redhat:enterprise_linux:ant-junit, p-cpe:/a:redhat:enterprise_linux:apache-commons-net, p-cpe:/a:redhat:enterprise_linux:apache-ivy, p-cpe:/a:redhat:enterprise_linux:apache-parent, p-cpe:/a:redhat:enterprise_linux:apache-resource-bundles, p-cpe:/a:redhat:enterprise_linux:cdi-api, p-cpe:/a:redhat:enterprise_linux:hawtjni, p-cpe:/a:redhat:enterprise_linux:jansi-native, p-cpe:/a:redhat:enterprise_linux:jsch, p-cpe:/a:redhat:enterprise_linux:jsoup, p-cpe:/a:redhat:enterprise_linux:jsr-305, p-cpe:/a:redhat:enterprise_linux:jzlib, p-cpe:/a:redhat:enterprise_linux:maven, p-cpe:/a:redhat:enterprise_linux:maven-artifact, p-cpe:/a:redhat:enterprise_linux:maven-artifact-manager, p-cpe:/a:redhat:enterprise_linux:maven-artifact-resolver, p-cpe:/a:redhat:enterprise_linux:maven-common-artifact-filters, p-cpe:/a:redhat:enterprise_linux:maven-compiler-plugin, p-cpe:/a:redhat:enterprise_linux:maven-file-management, p-cpe:/a:redhat:enterprise_linux:maven-filtering, p-cpe:/a:redhat:enterprise_linux:maven-invoker, p-cpe:/a:redhat:enterprise_linux:maven-model, p-cpe:/a:redhat:enterprise_linux:maven-monitor, p-cpe:/a:redhat:enterprise_linux:maven-parent, p-cpe:/a:redhat:enterprise_linux:maven-plugin-registry, p-cpe:/a:redhat:enterprise_linux:maven-profile, p-cpe:/a:redhat:enterprise_linux:maven-project, p-cpe:/a:redhat:enterprise_linux:maven-remote-resources-plugin, p-cpe:/a:redhat:enterprise_linux:maven-settings, p-cpe:/a:redhat:enterprise_linux:maven-shared-incremental, p-cpe:/a:redhat:enterprise_linux:maven-shared-io, p-cpe:/a:redhat:enterprise_linux:maven-shared-utils, p-cpe:/a:redhat:enterprise_linux:maven-toolchain, p-cpe:/a:redhat:enterprise_linux:maven-wagon, p-cpe:/a:redhat:enterprise_linux:modello, p-cpe:/a:redhat:enterprise_linux:plexus-build-api, p-cpe:/a:redhat:enterprise_linux:plexus-cipher, p-cpe:/a:redhat:enterprise_linux:plexus-classworlds, p-cpe:/a:redhat:enterprise_linux:plexus-compiler, p-cpe:/a:redhat:enterprise_linux:plexus-component-api, p-cpe:/a:redhat:enterprise_linux:plexus-containers-component-annotations, p-cpe:/a:redhat:enterprise_linux:plexus-containers-container-default, p-cpe:/a:redhat:enterprise_linux:plexus-interactivity, p-cpe:/a:redhat:enterprise_linux:plexus-interpolation, p-cpe:/a:redhat:enterprise_linux:plexus-resources, p-cpe:/a:redhat:enterprise_linux:plexus-sec-dispatcher, p-cpe:/a:redhat:enterprise_linux:plexus-utils, p-cpe:/a:redhat:enterprise_linux:plexus-velocity, p-cpe:/a:redhat:enterprise_linux:xbean, p-cpe:/a:redhat:enterprise_linux:slf4j-javadoc, p-cpe:/a:redhat:enterprise_linux:slf4j-manual, p-cpe:/a:redhat:enterprise_linux:maven-shared-utils-javadoc, p-cpe:/a:redhat:enterprise_linux:apache-commons-io, p-cpe:/a:redhat:enterprise_linux:apache-commons-lang3, p-cpe:/a:redhat:enterprise_linux:apache-commons-logging, p-cpe:/a:redhat:enterprise_linux:geronimo-annotation, p-cpe:/a:redhat:enterprise_linux:glassfish-el-api, p-cpe:/a:redhat:enterprise_linux:guava20, p-cpe:/a:redhat:enterprise_linux:hawtjni-runtime, p-cpe:/a:redhat:enterprise_linux:jboss-interceptors-1.2-api, p-cpe:/a:redhat:enterprise_linux:maven-lib, p-cpe:/a:redhat:enterprise_linux:maven-resolver-api, p-cpe:/a:redhat:enterprise_linux:maven-resolver-connector-basic, p-cpe:/a:redhat:enterprise_linux:maven-resolver-impl, p-cpe:/a:redhat:enterprise_linux:maven-resolver-spi, p-cpe:/a:redhat:enterprise_linux:maven-resolver-transport-wagon, p-cpe:/a:redhat:enterprise_linux:maven-resolver-util, p-cpe:/a:redhat:enterprise_linux:maven-wagon-file, p-cpe:/a:redhat:enterprise_linux:maven-wagon-http, p-cpe:/a:redhat:enterprise_linux:maven-wagon-http-shared, p-cpe:/a:redhat:enterprise_linux:maven-wagon-provider-api, p-cpe:/a:redhat:enterprise_linux:sisu-inject, p-cpe:/a:redhat:enterprise_linux:sisu-plexus, p-cpe:/a:redhat:enterprise_linux:maven-resolver, p-cpe:/a:redhat:enterprise_linux:sisu, p-cpe:/a:redhat:enterprise_linux:apache-commons-compress, p-cpe:/a:redhat:enterprise_linux:apache-commons-compress-javadoc, p-cpe:/a:redhat:enterprise_linux:bcel-javadoc, p-cpe:/a:redhat:enterprise_linux:ant, p-cpe:/a:redhat:enterprise_linux:ant-antlr, p-cpe:/a:redhat:enterprise_linux:ant-apache-bcel, p-cpe:/a:redhat:enterprise_linux:ant-apache-bsf, p-cpe:/a:redhat:enterprise_linux:ant-apache-log4j, p-cpe:/a:redhat:enterprise_linux:ant-apache-oro, p-cpe:/a:redhat:enterprise_linux:ant-apache-regexp, p-cpe:/a:redhat:enterprise_linux:ant-apache-resolver, p-cpe:/a:redhat:enterprise_linux:ant-commons-logging, p-cpe:/a:redhat:enterprise_linux:ant-commons-net, p-cpe:/a:redhat:enterprise_linux:ant-javamail, p-cpe:/a:redhat:enterprise_linux:ant-jdepend, p-cpe:/a:redhat:enterprise_linux:ant-jmf, p-cpe:/a:redhat:enterprise_linux:ant-jsch, p-cpe:/a:redhat:enterprise_linux:ant-swing, p-cpe:/a:redhat:enterprise_linux:maven2, p-cpe:/a:redhat:enterprise_linux:plexus-containers, p-cpe:/a:redhat:enterprise_linux:apache-commons-jxpath, p-cpe:/a:redhat:enterprise_linux:apache-commons-jxpath-javadoc, p-cpe:/a:redhat:enterprise_linux:log4j12, p-cpe:/a:redhat:enterprise_linux:log4j12-javadoc, p-cpe:/a:redhat:enterprise_linux:glassfish-el, p-cpe:/a:redhat:enterprise_linux:junit, p-cpe:/a:redhat:enterprise_linux:testng, cpe:/o:redhat:rhel_eus:8.10, p-cpe:/a:redhat:enterprise_linux:javapackages-tools, p-cpe:/a:redhat:enterprise_linux:ant-apache-xalan2, p-cpe:/a:redhat:enterprise_linux:ant-contrib, p-cpe:/a:redhat:enterprise_linux:ant-contrib-javadoc, p-cpe:/a:redhat:enterprise_linux:ant-javadoc, p-cpe:/a:redhat:enterprise_linux:ant-lib, p-cpe:/a:redhat:enterprise_linux:ant-manual, p-cpe:/a:redhat:enterprise_linux:ant-testutil, p-cpe:/a:redhat:enterprise_linux:ant-xz, p-cpe:/a:redhat:enterprise_linux:antlr-javadoc, p-cpe:/a:redhat:enterprise_linux:antlr-manual, p-cpe:/a:redhat:enterprise_linux:antlr-tool, p-cpe:/a:redhat:enterprise_linux:aopalliance-javadoc, p-cpe:/a:redhat:enterprise_linux:apache-commons-cli-javadoc, p-cpe:/a:redhat:enterprise_linux:apache-commons-codec-javadoc, p-cpe:/a:redhat:enterprise_linux:apache-commons-exec, p-cpe:/a:redhat:enterprise_linux:apache-commons-exec-javadoc, p-cpe:/a:redhat:enterprise_linux:apache-commons-io-javadoc, p-cpe:/a:redhat:enterprise_linux:apache-commons-lang3-javadoc, p-cpe:/a:redhat:enterprise_linux:apache-commons-lang-javadoc, p-cpe:/a:redhat:enterprise_linux:apache-commons-logging-javadoc, p-cpe:/a:redhat:enterprise_linux:apache-commons-net-javadoc, p-cpe:/a:redhat:enterprise_linux:apache-commons-parent, p-cpe:/a:redhat:enterprise_linux:apache-ivy-javadoc, p-cpe:/a:redhat:enterprise_linux:aqute-bnd, p-cpe:/a:redhat:enterprise_linux:aqute-bnd-javadoc, p-cpe:/a:redhat:enterprise_linux:aqute-bndlib, p-cpe:/a:redhat:enterprise_linux:assertj-core, p-cpe:/a:redhat:enterprise_linux:assertj-core-javadoc, p-cpe:/a:redhat:enterprise_linux:atinject-javadoc, p-cpe:/a:redhat:enterprise_linux:atinject-tck, p-cpe:/a:redhat:enterprise_linux:beust-jcommander, p-cpe:/a:redhat:enterprise_linux:beust-jcommander-javadoc, p-cpe:/a:redhat:enterprise_linux:bnd-maven-plugin, p-cpe:/a:redhat:enterprise_linux:bsf-javadoc, p-cpe:/a:redhat:enterprise_linux:bsh-javadoc, p-cpe:/a:redhat:enterprise_linux:bsh-manual, p-cpe:/a:redhat:enterprise_linux:byaccj, p-cpe:/a:redhat:enterprise_linux:cal10n-javadoc, p-cpe:/a:redhat:enterprise_linux:cdi-api-javadoc, p-cpe:/a:redhat:enterprise_linux:cglib-javadoc, p-cpe:/a:redhat:enterprise_linux:easymock, p-cpe:/a:redhat:enterprise_linux:easymock-javadoc, p-cpe:/a:redhat:enterprise_linux:exec-maven-plugin, p-cpe:/a:redhat:enterprise_linux:exec-maven-plugin-javadoc, p-cpe:/a:redhat:enterprise_linux:felix-osgi-compendium, p-cpe:/a:redhat:enterprise_linux:felix-osgi-compendium-javadoc, p-cpe:/a:redhat:enterprise_linux:felix-osgi-core, p-cpe:/a:redhat:enterprise_linux:felix-osgi-core-javadoc, p-cpe:/a:redhat:enterprise_linux:felix-osgi-foundation, p-cpe:/a:redhat:enterprise_linux:felix-osgi-foundation-javadoc, p-cpe:/a:redhat:enterprise_linux:felix-parent, p-cpe:/a:redhat:enterprise_linux:felix-utils, p-cpe:/a:redhat:enterprise_linux:felix-utils-javadoc, p-cpe:/a:redhat:enterprise_linux:forge-parent, p-cpe:/a:redhat:enterprise_linux:fusesource-pom, p-cpe:/a:redhat:enterprise_linux:geronimo-annotation-javadoc, p-cpe:/a:redhat:enterprise_linux:geronimo-jms, p-cpe:/a:redhat:enterprise_linux:geronimo-jms-javadoc, p-cpe:/a:redhat:enterprise_linux:geronimo-jpa, p-cpe:/a:redhat:enterprise_linux:geronimo-jpa-javadoc, p-cpe:/a:redhat:enterprise_linux:geronimo-parent-poms, p-cpe:/a:redhat:enterprise_linux:glassfish-annotation-api, p-cpe:/a:redhat:enterprise_linux:glassfish-annotation-api-javadoc, p-cpe:/a:redhat:enterprise_linux:glassfish-el-javadoc, p-cpe:/a:redhat:enterprise_linux:glassfish-jsp-api, p-cpe:/a:redhat:enterprise_linux:glassfish-jsp-api-javadoc, p-cpe:/a:redhat:enterprise_linux:glassfish-legal, p-cpe:/a:redhat:enterprise_linux:glassfish-master-pom, p-cpe:/a:redhat:enterprise_linux:glassfish-servlet-api, p-cpe:/a:redhat:enterprise_linux:glassfish-servlet-api-javadoc, p-cpe:/a:redhat:enterprise_linux:google-guice-javadoc, p-cpe:/a:redhat:enterprise_linux:guava20-javadoc, p-cpe:/a:redhat:enterprise_linux:guava20-testlib, p-cpe:/a:redhat:enterprise_linux:guice-assistedinject, p-cpe:/a:redhat:enterprise_linux:guice-bom, p-cpe:/a:redhat:enterprise_linux:guice-extensions, p-cpe:/a:redhat:enterprise_linux:guice-grapher, p-cpe:/a:redhat:enterprise_linux:guice-jmx, p-cpe:/a:redhat:enterprise_linux:guice-jndi, p-cpe:/a:redhat:enterprise_linux:guice-multibindings, p-cpe:/a:redhat:enterprise_linux:guice-parent, p-cpe:/a:redhat:enterprise_linux:guice-servlet, p-cpe:/a:redhat:enterprise_linux:guice-testlib, p-cpe:/a:redhat:enterprise_linux:guice-throwingproviders, p-cpe:/a:redhat:enterprise_linux:hamcrest, p-cpe:/a:redhat:enterprise_linux:hamcrest-core, p-cpe:/a:redhat:enterprise_linux:hamcrest-demo, p-cpe:/a:redhat:enterprise_linux:hamcrest-javadoc, p-cpe:/a:redhat:enterprise_linux:hawtjni-javadoc, p-cpe:/a:redhat:enterprise_linux:httpcomponents-client-cache, p-cpe:/a:redhat:enterprise_linux:httpcomponents-core-javadoc, p-cpe:/a:redhat:enterprise_linux:isorelax-javadoc, p-cpe:/a:redhat:enterprise_linux:ivy-local, p-cpe:/a:redhat:enterprise_linux:jakarta-oro-javadoc, p-cpe:/a:redhat:enterprise_linux:jansi-javadoc, p-cpe:/a:redhat:enterprise_linux:jansi-native-javadoc, p-cpe:/a:redhat:enterprise_linux:java_cup, p-cpe:/a:redhat:enterprise_linux:java_cup-javadoc, p-cpe:/a:redhat:enterprise_linux:java_cup-manual, p-cpe:/a:redhat:enterprise_linux:javacc, p-cpe:/a:redhat:enterprise_linux:javacc-demo, p-cpe:/a:redhat:enterprise_linux:javacc-javadoc, p-cpe:/a:redhat:enterprise_linux:javacc-manual, p-cpe:/a:redhat:enterprise_linux:javacc-maven-plugin, p-cpe:/a:redhat:enterprise_linux:javacc-maven-plugin-javadoc, p-cpe:/a:redhat:enterprise_linux:javamail, p-cpe:/a:redhat:enterprise_linux:javamail-javadoc, p-cpe:/a:redhat:enterprise_linux:javapackages-filesystem, p-cpe:/a:redhat:enterprise_linux:javapackages-local, p-cpe:/a:redhat:enterprise_linux:jaxen-demo, p-cpe:/a:redhat:enterprise_linux:jaxen-javadoc, p-cpe:/a:redhat:enterprise_linux:jboss-interceptors-1.2-api-javadoc, p-cpe:/a:redhat:enterprise_linux:jdepend, p-cpe:/a:redhat:enterprise_linux:jdepend-demo, p-cpe:/a:redhat:enterprise_linux:jdepend-javadoc, p-cpe:/a:redhat:enterprise_linux:jdependency, p-cpe:/a:redhat:enterprise_linux:jdependency-javadoc, p-cpe:/a:redhat:enterprise_linux:jdom2, p-cpe:/a:redhat:enterprise_linux:jdom2-javadoc, p-cpe:/a:redhat:enterprise_linux:jdom-demo, p-cpe:/a:redhat:enterprise_linux:jdom-javadoc, p-cpe:/a:redhat:enterprise_linux:jflex, p-cpe:/a:redhat:enterprise_linux:jflex-javadoc, p-cpe:/a:redhat:enterprise_linux:jline, p-cpe:/a:redhat:enterprise_linux:jline-javadoc, p-cpe:/a:redhat:enterprise_linux:jsch-javadoc, p-cpe:/a:redhat:enterprise_linux:jsoup-javadoc, p-cpe:/a:redhat:enterprise_linux:jsr-305-javadoc, p-cpe:/a:redhat:enterprise_linux:jtidy, p-cpe:/a:redhat:enterprise_linux:jtidy-javadoc, p-cpe:/a:redhat:enterprise_linux:jul-to-slf4j, p-cpe:/a:redhat:enterprise_linux:junit-javadoc, p-cpe:/a:redhat:enterprise_linux:junit-manual, p-cpe:/a:redhat:enterprise_linux:jvnet-parent, p-cpe:/a:redhat:enterprise_linux:jzlib-demo, p-cpe:/a:redhat:enterprise_linux:jzlib-javadoc, p-cpe:/a:redhat:enterprise_linux:log4j-over-slf4j, p-cpe:/a:redhat:enterprise_linux:maven2-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-antrun-plugin, p-cpe:/a:redhat:enterprise_linux:maven-antrun-plugin-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-archiver, p-cpe:/a:redhat:enterprise_linux:maven-archiver-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-artifact-resolver-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-artifact-transfer, p-cpe:/a:redhat:enterprise_linux:maven-artifact-transfer-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-assembly-plugin, p-cpe:/a:redhat:enterprise_linux:maven-assembly-plugin-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-cal10n-plugin, p-cpe:/a:redhat:enterprise_linux:maven-clean-plugin, p-cpe:/a:redhat:enterprise_linux:maven-clean-plugin-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-common-artifact-filters-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-compiler-plugin-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-dependency-analyzer, p-cpe:/a:redhat:enterprise_linux:maven-dependency-analyzer-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-dependency-plugin, p-cpe:/a:redhat:enterprise_linux:maven-dependency-plugin-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-dependency-tree, p-cpe:/a:redhat:enterprise_linux:maven-dependency-tree-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-doxia, p-cpe:/a:redhat:enterprise_linux:maven-doxia-core, p-cpe:/a:redhat:enterprise_linux:maven-doxia-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-doxia-logging-api, p-cpe:/a:redhat:enterprise_linux:maven-doxia-module-apt, p-cpe:/a:redhat:enterprise_linux:maven-doxia-module-confluence, p-cpe:/a:redhat:enterprise_linux:maven-doxia-module-docbook-simple, p-cpe:/a:redhat:enterprise_linux:maven-doxia-module-fml, p-cpe:/a:redhat:enterprise_linux:maven-doxia-module-latex, p-cpe:/a:redhat:enterprise_linux:maven-doxia-module-rtf, p-cpe:/a:redhat:enterprise_linux:maven-doxia-module-twiki, p-cpe:/a:redhat:enterprise_linux:maven-doxia-module-xdoc, p-cpe:/a:redhat:enterprise_linux:maven-doxia-module-xhtml, p-cpe:/a:redhat:enterprise_linux:maven-doxia-modules, p-cpe:/a:redhat:enterprise_linux:maven-doxia-sink-api, p-cpe:/a:redhat:enterprise_linux:maven-doxia-sitetools, p-cpe:/a:redhat:enterprise_linux:maven-doxia-sitetools-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-doxia-test-docs, p-cpe:/a:redhat:enterprise_linux:maven-doxia-tests, p-cpe:/a:redhat:enterprise_linux:maven-enforcer, p-cpe:/a:redhat:enterprise_linux:maven-enforcer-api, p-cpe:/a:redhat:enterprise_linux:maven-enforcer-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-enforcer-plugin, p-cpe:/a:redhat:enterprise_linux:maven-enforcer-rules, p-cpe:/a:redhat:enterprise_linux:maven-failsafe-plugin, p-cpe:/a:redhat:enterprise_linux:maven-file-management-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-filtering-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-hawtjni-plugin, p-cpe:/a:redhat:enterprise_linux:maven-install-plugin, p-cpe:/a:redhat:enterprise_linux:maven-install-plugin-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-invoker-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-invoker-plugin, p-cpe:/a:redhat:enterprise_linux:maven-invoker-plugin-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-jar-plugin, p-cpe:/a:redhat:enterprise_linux:maven-jar-plugin-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-local, p-cpe:/a:redhat:enterprise_linux:maven-plugin-annotations, p-cpe:/a:redhat:enterprise_linux:maven-plugin-build-helper, p-cpe:/a:redhat:enterprise_linux:maven-plugin-build-helper-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-plugin-bundle, p-cpe:/a:redhat:enterprise_linux:maven-plugin-bundle-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-plugin-descriptor, p-cpe:/a:redhat:enterprise_linux:maven-plugin-plugin, p-cpe:/a:redhat:enterprise_linux:maven-plugin-testing, p-cpe:/a:redhat:enterprise_linux:maven-plugin-testing-harness, p-cpe:/a:redhat:enterprise_linux:maven-plugin-testing-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-plugin-testing-tools, p-cpe:/a:redhat:enterprise_linux:maven-plugin-tools, p-cpe:/a:redhat:enterprise_linux:maven-plugin-tools-annotations, p-cpe:/a:redhat:enterprise_linux:maven-plugin-tools-ant, p-cpe:/a:redhat:enterprise_linux:maven-plugin-tools-api, p-cpe:/a:redhat:enterprise_linux:maven-plugin-tools-beanshell, p-cpe:/a:redhat:enterprise_linux:maven-plugin-tools-generators, p-cpe:/a:redhat:enterprise_linux:maven-plugin-tools-java, p-cpe:/a:redhat:enterprise_linux:maven-plugin-tools-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-plugin-tools-javadocs, p-cpe:/a:redhat:enterprise_linux:maven-plugin-tools-model, p-cpe:/a:redhat:enterprise_linux:maven-plugins-pom, p-cpe:/a:redhat:enterprise_linux:maven-remote-resources-plugin-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-reporting-api, p-cpe:/a:redhat:enterprise_linux:maven-reporting-api-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-reporting-impl, p-cpe:/a:redhat:enterprise_linux:maven-reporting-impl-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-resolver-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-resolver-test-util, p-cpe:/a:redhat:enterprise_linux:maven-resolver-transport-classpath, p-cpe:/a:redhat:enterprise_linux:maven-resolver-transport-file, p-cpe:/a:redhat:enterprise_linux:maven-resolver-transport-http, p-cpe:/a:redhat:enterprise_linux:maven-resources-plugin, p-cpe:/a:redhat:enterprise_linux:maven-resources-plugin-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-script, p-cpe:/a:redhat:enterprise_linux:maven-script-ant, p-cpe:/a:redhat:enterprise_linux:maven-script-beanshell, p-cpe:/a:redhat:enterprise_linux:maven-script-interpreter, p-cpe:/a:redhat:enterprise_linux:maven-script-interpreter-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-shade-plugin, p-cpe:/a:redhat:enterprise_linux:maven-shade-plugin-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-shared, p-cpe:/a:redhat:enterprise_linux:maven-shared-incremental-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-shared-io-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-source-plugin, p-cpe:/a:redhat:enterprise_linux:maven-source-plugin-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-surefire, p-cpe:/a:redhat:enterprise_linux:maven-surefire-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-surefire-plugin, p-cpe:/a:redhat:enterprise_linux:maven-surefire-provider-junit, p-cpe:/a:redhat:enterprise_linux:maven-surefire-provider-testng, p-cpe:/a:redhat:enterprise_linux:maven-surefire-report-parser, p-cpe:/a:redhat:enterprise_linux:maven-surefire-report-plugin, p-cpe:/a:redhat:enterprise_linux:maven-test-tools, p-cpe:/a:redhat:enterprise_linux:maven-verifier, p-cpe:/a:redhat:enterprise_linux:maven-verifier-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-wagon-ftp, p-cpe:/a:redhat:enterprise_linux:maven-wagon-http-lightweight, p-cpe:/a:redhat:enterprise_linux:maven-wagon-javadoc, p-cpe:/a:redhat:enterprise_linux:maven-wagon-providers, p-cpe:/a:redhat:enterprise_linux:mockito, p-cpe:/a:redhat:enterprise_linux:mockito-javadoc, p-cpe:/a:redhat:enterprise_linux:modello-javadoc, p-cpe:/a:redhat:enterprise_linux:mojo-parent, p-cpe:/a:redhat:enterprise_linux:munge-maven-plugin, p-cpe:/a:redhat:enterprise_linux:munge-maven-plugin-javadoc, p-cpe:/a:redhat:enterprise_linux:objectweb-pom, p-cpe:/a:redhat:enterprise_linux:objenesis, p-cpe:/a:redhat:enterprise_linux:objenesis-javadoc, p-cpe:/a:redhat:enterprise_linux:os-maven-plugin, p-cpe:/a:redhat:enterprise_linux:os-maven-plugin-javadoc, p-cpe:/a:redhat:enterprise_linux:osgi-annotation, p-cpe:/a:redhat:enterprise_linux:osgi-annotation-javadoc, p-cpe:/a:redhat:enterprise_linux:osgi-compendium, p-cpe:/a:redhat:enterprise_linux:osgi-compendium-javadoc, p-cpe:/a:redhat:enterprise_linux:osgi-core, p-cpe:/a:redhat:enterprise_linux:osgi-core-javadoc, p-cpe:/a:redhat:enterprise_linux:plexus-ant-factory, p-cpe:/a:redhat:enterprise_linux:plexus-ant-factory-javadoc, p-cpe:/a:redhat:enterprise_linux:plexus-bsh-factory, p-cpe:/a:redhat:enterprise_linux:plexus-bsh-factory-javadoc, p-cpe:/a:redhat:enterprise_linux:plexus-build-api-javadoc, p-cpe:/a:redhat:enterprise_linux:plexus-cipher-javadoc, p-cpe:/a:redhat:enterprise_linux:plexus-classworlds-javadoc, p-cpe:/a:redhat:enterprise_linux:plexus-cli, p-cpe:/a:redhat:enterprise_linux:plexus-cli-javadoc, p-cpe:/a:redhat:enterprise_linux:plexus-compiler-extras, p-cpe:/a:redhat:enterprise_linux:plexus-compiler-javadoc, p-cpe:/a:redhat:enterprise_linux:plexus-compiler-pom, p-cpe:/a:redhat:enterprise_linux:plexus-component-api-javadoc, p-cpe:/a:redhat:enterprise_linux:plexus-component-factories-pom, p-cpe:/a:redhat:enterprise_linux:plexus-components-pom, p-cpe:/a:redhat:enterprise_linux:plexus-containers-component-javadoc, p-cpe:/a:redhat:enterprise_linux:plexus-containers-component-metadata, p-cpe:/a:redhat:enterprise_linux:plexus-containers-javadoc, p-cpe:/a:redhat:enterprise_linux:plexus-i18n, p-cpe:/a:redhat:enterprise_linux:plexus-i18n-javadoc, p-cpe:/a:redhat:enterprise_linux:plexus-interactivity-api, p-cpe:/a:redhat:enterprise_linux:plexus-interactivity-javadoc, p-cpe:/a:redhat:enterprise_linux:plexus-interactivity-jline, p-cpe:/a:redhat:enterprise_linux:plexus-interpolation-javadoc, p-cpe:/a:redhat:enterprise_linux:plexus-io, p-cpe:/a:redhat:enterprise_linux:plexus-io-javadoc, p-cpe:/a:redhat:enterprise_linux:plexus-languages, p-cpe:/a:redhat:enterprise_linux:plexus-languages-javadoc, p-cpe:/a:redhat:enterprise_linux:plexus-pom, p-cpe:/a:redhat:enterprise_linux:plexus-resources-javadoc, p-cpe:/a:redhat:enterprise_linux:plexus-sec-dispatcher-javadoc, p-cpe:/a:redhat:enterprise_linux:plexus-utils-javadoc, p-cpe:/a:redhat:enterprise_linux:plexus-velocity-javadoc, p-cpe:/a:redhat:enterprise_linux:powermock, p-cpe:/a:redhat:enterprise_linux:powermock-api-easymock, p-cpe:/a:redhat:enterprise_linux:powermock-api-mockito, p-cpe:/a:redhat:enterprise_linux:powermock-api-support, p-cpe:/a:redhat:enterprise_linux:powermock-common, p-cpe:/a:redhat:enterprise_linux:powermock-core, p-cpe:/a:redhat:enterprise_linux:powermock-javadoc, p-cpe:/a:redhat:enterprise_linux:powermock-junit4, p-cpe:/a:redhat:enterprise_linux:powermock-reflect, p-cpe:/a:redhat:enterprise_linux:powermock-testng, p-cpe:/a:redhat:enterprise_linux:python3-javapackages, p-cpe:/a:redhat:enterprise_linux:qdox, p-cpe:/a:redhat:enterprise_linux:qdox-javadoc, p-cpe:/a:redhat:enterprise_linux:regexp-javadoc, p-cpe:/a:redhat:enterprise_linux:sisu-javadoc, p-cpe:/a:redhat:enterprise_linux:sisu-mojos, p-cpe:/a:redhat:enterprise_linux:sisu-mojos-javadoc, p-cpe:/a:redhat:enterprise_linux:slf4j-ext, p-cpe:/a:redhat:enterprise_linux:slf4j-jcl, p-cpe:/a:redhat:enterprise_linux:slf4j-log4j12, p-cpe:/a:redhat:enterprise_linux:slf4j-sources, p-cpe:/a:redhat:enterprise_linux:sonatype-oss-parent, p-cpe:/a:redhat:enterprise_linux:sonatype-plugins-parent, p-cpe:/a:redhat:enterprise_linux:spec-version-maven-plugin, p-cpe:/a:redhat:enterprise_linux:spec-version-maven-plugin-javadoc, p-cpe:/a:redhat:enterprise_linux:spice-parent, p-cpe:/a:redhat:enterprise_linux:testng-javadoc, p-cpe:/a:redhat:enterprise_linux:velocity-demo, p-cpe:/a:redhat:enterprise_linux:velocity-javadoc, p-cpe:/a:redhat:enterprise_linux:velocity-manual, p-cpe:/a:redhat:enterprise_linux:weld-parent, p-cpe:/a:redhat:enterprise_linux:xbean-javadoc, p-cpe:/a:redhat:enterprise_linux:xml-commons-apis-javadoc, p-cpe:/a:redhat:enterprise_linux:xml-commons-apis-manual, p-cpe:/a:redhat:enterprise_linux:xml-commons-resolver-javadoc, p-cpe:/a:redhat:enterprise_linux:xmlunit, p-cpe:/a:redhat:enterprise_linux:xmlunit-javadoc, p-cpe:/a:redhat:enterprise_linux:xmvn, p-cpe:/a:redhat:enterprise_linux:xmvn-api, p-cpe:/a:redhat:enterprise_linux:xmvn-bisect, p-cpe:/a:redhat:enterprise_linux:xmvn-connector-aether, p-cpe:/a:redhat:enterprise_linux:xmvn-connector-ivy, p-cpe:/a:redhat:enterprise_linux:xmvn-core, p-cpe:/a:redhat:enterprise_linux:xmvn-install, p-cpe:/a:redhat:enterprise_linux:xmvn-javadoc, p-cpe:/a:redhat:enterprise_linux:xmvn-minimal, p-cpe:/a:redhat:enterprise_linux:xmvn-mojo, p-cpe:/a:redhat:enterprise_linux:xmvn-parent-pom, p-cpe:/a:redhat:enterprise_linux:xmvn-resolve, p-cpe:/a:redhat:enterprise_linux:xmvn-subst, p-cpe:/a:redhat:enterprise_linux:xmvn-tools-pom, p-cpe:/a:redhat:enterprise_linux:xz-java, p-cpe:/a:redhat:enterprise_linux:xz-java-javadoc, p-cpe:/a:redhat:enterprise_linux:antlr-c%2b%2b

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 6/23/2025

Vulnerability Publication Date: 8/20/2019

Reference Information

CVE: CVE-2019-10086, CVE-2025-48734

CWE: 284, 502

RHSA: 2025:9318