CVE Database
/

CVE-2019-17555

Back to search

CVE-2019-17555

Published: Dec 4, 2019

Modified: Aug 5, 2024

PUBLISHED

Description

The AsyncResponseWrapperImpl class in Apache Olingo versions 4.0.0 to 4.6.0 reads the Retry-After header and passes it to the Thread.sleep() method without any check. If a malicious server returns a huge value in the header, then it can help to implement a DoS attack.

VendorProductVersions

Apache

Olingo

affected
4.0.0 to 4.6.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now