CVE-2019-17554: XEE
The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Request with content type "application/xml", which trigger the deserialization of entities, can be used to trigger XXE attacks.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-17554?
CVE-2019-17554 is a vulnerability in Apache Olingo versions 4.0.0 to 4.6.0 that allows XML content type entity deserialization, leading to potential XXE attacks.
What is the severity of CVE-2019-17554?
The severity of CVE-2019-17554 is medium with a severity value of 5.5.
How does CVE-2019-17554 affect Apache Olingo?
CVE-2019-17554 affects Apache Olingo versions 4.0.0 to 4.6.0.
How can CVE-2019-17554 be exploited?
CVE-2019-17554 can be exploited by sending a request with content type "application/xml" to trigger the deserialization of entities and perform XXE attacks.
Is there a fix for CVE-2019-17554?
To fix CVE-2019-17554, update to a version of Apache Olingo that is later than 4.6.0.