CVE-2019-17554 EXPLOIT
5.5
MEDIUM · CVSS 3.1 · EPSS 12.2% (pctl 96)
Patch early
A public exploit exists.
Description
The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Request with content type "application/xml", which trigger the deserialization of entities, can be used to trigger XXE attacks.
Scoring
| CVSS | 5.5 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
| EPSS | 12.25% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-611 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-12-04 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| apache | olingo |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Apache Olingo OData 4.0 - XML External Entity Injection | 2019-12-11 |
References
- http://packetstormsecurity.com/files/155619/Apache-Olingo-OData-4.6.x-XML-Injection.html
- https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E
- https://mail-archives.apache.org/mod_mbox/olingo-user/201912.mbox/%3CCAGSZ4d7Ty%3DL-n_iAzT6vcQp65BY29XZDS5tMoM8MdDrb1moM7A%40mail.gmail.com%3E
- https://seclists.org/bugtraq/2019/Dec/11
- http://packetstormsecurity.com/files/155619/Apache-Olingo-OData-4.6.x-XML-Injection.html
- https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E
- https://mail-archives.apache.org/mod_mbox/olingo-user/201912.mbox/%3CCAGSZ4d7Ty%3DL-n_iAzT6vcQp65BY29XZDS5tMoM8MdDrb1moM7A%40mail.gmail.com%3E
- https://seclists.org/bugtraq/2019/Dec/11
→ the Explorer · watch your stack · NVD