Lucene search

K
cvelistApacheCVELIST:CVE-2019-17556
HistoryDec 04, 2019 - 4:59 p.m.

CVE-2019-17556

2019-12-0416:59:49
apache
www.cve.org

9.5 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.1%

Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn’t check classes being deserialized. If an attacker can feed malicious metadata to the class, then it may result in running attacker’s code in the worse case.

CNA Affected

[
  {
    "product": "Olingo",
    "vendor": "Apache",
    "versions": [
      {
        "status": "affected",
        "version": "4.0.0 to 4.6.0"
      }
    ]
  }
]

9.5 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.1%

Related for CVELIST:CVE-2019-17556