Lucene search

K
osvGoogleOSV:CVE-2019-17556
HistoryDec 04, 2019 - 5:16 p.m.

CVE-2019-17556

2019-12-0417:16:43
Google
osv.dev
4

6.9 Medium

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.1%

Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn’t check classes being deserialized. If an attacker can feed malicious metadata to the class, then it may result in running attacker’s code in the worse case.

6.9 Medium

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.1%

Related for OSV:CVE-2019-17556