peter bassill · operator
$ cve CVE-2019-17556 JSON

CVE-2019-17556

9.8
CRITICAL · CVSS 3.1 · EPSS 3.6% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being deserialized. If an attacker can feed malicious metadata to the class, then it may result in running attacker's code in the worse case.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.62% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2019-12-04
Last modified2026-06-17

Affected (1)

VendorProduct
apacheolingo

References

→ the Explorer  ·  watch your stack  ·  NVD