Critical Vulnerabilities in Apache Commons BeanUtils and mod_jk Affect Ubuntu 18.04 LTS

Critical Vulnerabilities in Apache Commons BeanUtils and mod_jk Affect Ubuntu 18.04 LTS

First seen 23 Jul 2026, 14:24 UTC launchpad.netUbuntuLinuxsecurity 86% similarity 72.0

Article Content

Browse articles
ThreatCluster

Recent updates for Ubuntu 18.04 LTS revealed critical vulnerabilities in Apache Commons BeanUtils and mod_jk. The first issue, CVE-2014-0114 and CVE-2019-10086, allows attackers to execute arbitrary code due to improper property access. The second, CVE-2023-41081, exposes sensitive information or leads to denial of service via incorrect shared memory permissions. Both vulnerabilities were initially fixed in prior updates but were dropped during the update preparation phase. Users are advised to update their systems to mitigate these risks. The vulnerabilities impact systems running Ubuntu 18.04 LTS and require immediate attention from administrators. Ubuntu Pro provides extended security coverage for affected packages.

Key Points: • CVE-2014-0114 and CVE-2019-10086 allow arbitrary code execution in Apache Commons BeanUtils. • CVE-2023-41081 exposes sensitive data or causes denial of service in mod_jk. • Users of Ubuntu 18.04 LTS must update their systems to address these critical vulnerabilities.

ThreatCluster AI

Timeline

2014-04-30
CVE-2014-0114 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2019-08-20
CVE-2019-10086 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-09-13
CVE-2023-41081 published
Apache Tomcat Connectors had incorrect permissions for shared memory, allowing local attacks.
Ubuntu
2024-09-23
CVE-2024-46544 published
A vulnerability was published affecting libapache-mod-jk, necessitating updates.
launchpad.net
2025-05-28
CVE-2025-48734 published
A new vulnerability was disclosed affecting Apache Commons BeanUtils, requiring attention.
launchpad.net
2026-07-23
USN-8369-2 released
Ubuntu reintroduces the fix for CVE-2023-41081 after it was dropped in a prior update.
Ubuntu
2026-07-23
USN-8322-2 released
Ubuntu reintroduces fixes for CVE-2014-0114 and CVE-2019-10086 after they were dropped.
Ubuntu

Community

Browse all →