First published: Wed Dec 04 2019(Updated: )
The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Request with content type "application/xml", which trigger the deserialization of entities, can be used to trigger XXE attacks.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Olingo | >=4.0.0<=4.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17554 is a vulnerability in Apache Olingo versions 4.0.0 to 4.6.0 that allows XML content type entity deserialization, leading to potential XXE attacks.
The severity of CVE-2019-17554 is medium with a severity value of 5.5.
CVE-2019-17554 affects Apache Olingo versions 4.0.0 to 4.6.0.
CVE-2019-17554 can be exploited by sending a request with content type "application/xml" to trigger the deserialization of entities and perform XXE attacks.
To fix CVE-2019-17554, update to a version of Apache Olingo that is later than 4.6.0.