CVE-2019-17554

MEDIUMCVSS 5.5/10EPSS 12.25%

Last modified

CVE-2019-17554 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Request with content type "application/xml", which trigger the deserialization of entities, can be used to trigger XXE attacks.. EPSS estimates a 12.25% chance of exploitation in the next 30 days.

Description

The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Request with content type "application/xml", which trigger the deserialization of entities, can be used to trigger XXE attacks.

Metrics

CVSS 3.1
5.5/10

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS Probability
12.25%

95.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
ApacheOlingo>= 4.0.0, <= 4.6.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-17554?
The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Request with content type "application/xml", which trigger the deserialization of entities, can be used to trigger XXE attacks.
How severe is CVE-2019-17554?
CVE-2019-17554 has a CVSS score of 5.5/10 (MEDIUM severity). The EPSS model estimates a 12.25% probability of exploitation in the next 30 days.
How do I fix CVE-2019-17554?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-17554?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST