Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-17554

The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Request with content type "application/xml", which trigger the deserialization of entities, can be used to trigger XXE attacks.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.525
EPSS Ranking 97.8%
CVSS Severity
CVSS v3 Score 5.5
CVSS v2 Score 4.3
References
Products affected by CVE-2019-17554
  • Apache » Olingo » Version: 4.0.0
    cpe:2.3:a:apache:olingo:4.0.0
  • Apache » Olingo » Version: 4.1.0
    cpe:2.3:a:apache:olingo:4.1.0
  • Apache » Olingo » Version: 4.2.0
    cpe:2.3:a:apache:olingo:4.2.0
  • Apache » Olingo » Version: 4.3.0
    cpe:2.3:a:apache:olingo:4.3.0
  • Apache » Olingo » Version: 4.4.0
    cpe:2.3:a:apache:olingo:4.4.0
  • Apache » Olingo » Version: 4.6.0
    cpe:2.3:a:apache:olingo:4.6.0


Contact Us

Shodan ® - All rights reserved