CVE Database
/

CVE-2019-17554

Back to search

CVE-2019-17554

Published: Dec 4, 2019

Modified: Aug 5, 2024

PUBLISHED

Description

The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Request with content type "application/xml", which trigger the deserialization of entities, can be used to trigger XXE attacks.

VendorProductVersions

Apache

Olingo

affected
4.0.0 to 4.6.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now