The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Request with content type "application/xml", which trigger the deserialization of entities, can be used to trigger XXE attacks.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: apache

Published: 2019-12-04T16:54:22

Updated: 2020-01-31T08:06:09

Reserved: 2019-10-14T00:00:00


Link: CVE-2019-17554

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2019-12-04T17:16:43.867

Modified: 2023-11-07T03:06:19.423


Link: CVE-2019-17554

JSON object: View

cve-icon Redhat Information

No data.

CWE