Lucene search

K
prionPRIOn knowledge basePRION:CVE-2019-17556
HistoryDec 04, 2019 - 5:16 p.m.

Design/Logic Flaw

2019-12-0417:16:00
PRIOn knowledge base
www.prio-n.com
2

9.4 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.1%

Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn’t check classes being deserialized. If an attacker can feed malicious metadata to the class, then it may result in running attacker’s code in the worse case.

CPENameOperatorVersion
olingoge4.0.0
olingole4.6.0

9.4 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.1%

Related for PRION:CVE-2019-17556