V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2019-17554
CVE
MediumConfirmedExploit available

The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external enti…

CVSS
5.5
Medium
EPSS
0.53
p97
Published
2019-01-01
Updated
2019-01-01
Description

The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Request with content type "application/xml", which trigger the deserialization of entities, can be used to trigger XXE attacks.

Tags · CWE
CWE-611
CAPEC-221
Affected products
Olingo 4.0.0–4.6.0
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Timeline
2019-01-01
Published
2019-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.525 · p97
Known exploited (KEV)
No
Known exploits — Сканер-ВС
47770
exploitdb · https://www.exploit-db.com/exploits/47770
Enterprise
Affected software
ProductVendorStatus
olingo*Tracked
Source databases
CVE