---
title: "CVE-2014-0114\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2014-0114?format=md
keywords: index, follow
---

# CVE-2014-0114

Publication date 30 April 2014

Last updated 26 May 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar
in Apache Struts 1.x through 1.3.10 and in other products requiring
commons-beanutils through 1.9.2, does not suppress the class property,
which allows remote attackers to "manipulate" the ClassLoader and execute
arbitrary code via the class parameter, as demonstrated by the passing of
this parameter to the getClass method of the ActionForm object in Struts 1.

### From the Ubuntu Security Team

It was discovered that Apache Commons BeanUtils improperly handled certain
input. An attacker could use this vulnerability to execute arbitrary code.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| commons-beanutils | 23.04 lunar | Not affected |
| 22.10 kinetic | Not affected |
| 22.04 LTS jammy | Not affected |
| 21.10 impish | Not affected |
| 21.04 hirsute | Not affected |
| 20.10 groovy | Not affected |
| 20.04 LTS focal | Not affected |
| 19.10 eoan | Not affected |
| 19.04 disco | Not affected |
| 18.04 LTS bionic | Fixed 1.9.3-1ubuntu0.1~esm1  Ubuntu Pro |
| 16.04 LTS xenial | Fixed 1.9.2-3ubuntu0.1~esm1  Ubuntu Pro |
| 14.04 LTS trusty | Fixed 1.9.1-1ubuntu0.1~esm1  Ubuntu Pro |
| libstruts1.2-java | 23.04 lunar | Not in release |
| 22.10 kinetic | Not in release |
| 22.04 LTS jammy | Not in release |
| 21.10 impish | Not in release |
| 21.04 hirsute | Not in release |
| 20.10 groovy | Not in release |
| 20.04 LTS focal | Not in release |
| 19.10 eoan | Not in release |
| 19.04 disco | Not in release |
| 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 17.10 artful | Not in release |
| 17.04 zesty | Not in release |
| 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not in release |
| 15.04 vivid | Not in release |
| 14.10 utopic | Ignored end of life |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Fixed 1.2.9-5+deb7u1build0.12.04.1 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

### Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

[Get Ubuntu Pro](https://ubuntu.com/pro)
[30-day free trial](https://ubuntu.com/pro/free-trial)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0114)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2014-0114)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2014-0114)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2014-0114)

### Related Ubuntu Security Notices (USN)

+ [USN-4766-1](https://usn.ubuntu.com/USN-4766-1)
+ Apache Commons BeanUtils vulnerabilities
+ 15 March 2021

+ [USN-8322-2](https://usn.ubuntu.com/USN-8322-2)
+ Apache Commons BeanUtils regression
+ 23 July 2026

### Other references

* <https://bugzilla.redhat.com/show_bug.cgi?id=1091938>
* <https://www.cve.org/CVERecord?id=CVE-2014-0114>
