Record summary

CVE-2019-17554 has a selected CVSS score of 5.5 (medium); EIP currently links 1 catalogued exploit.

Description

The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Request with content type "application/xml", which trigger the deserialization of entities, can be used to trigger XXE attacks.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Apr 12, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE List, VulnCheck4.0.0 to 4.6.0affected

org.apache.olingo:odata-client-core

Browse Maven / org.apache.olingo:odata-client-core
GitHub Advisory4.0.0 to < 4.7.0 · Fixed in 4.7.0affected

org.apache.olingo:odata-server-core

Browse Maven / org.apache.olingo:odata-server-core
GitHub Advisory4.0.0 to < 4.7.0 · Fixed in 4.7.0affected

Proofs of concept

1

Catalogued exploits

ExploitDBApache Olingo OData 4.0 - XML External Entity InjectionExploitDB exploitby Compass SecurityNot analyzed1 file
ExploitDB

PoC details

References

9