CVE-2019-17556

Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being deserialized. If an attacker can feed malicious metadata to the class, then it may result in running attacker's code in the worse case.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:olingo:*:*:*:*:*:*:*:*

Information

Published : 2019-12-04 09:16

Updated : 2019-12-13 14:19


NVD link : CVE-2019-17556

Mitre link : CVE-2019-17556


JSON object : View

CWE
CWE-502

Deserialization of Untrusted Data

Advertisement

dedicated server usa

Products Affected

apache

  • olingo