Vulnerabilities > CVE-2019-17554 - XXE vulnerability in Apache Olingo

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
local
low complexity
apache
CWE-611
exploit available

Summary

The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Request with content type "application/xml", which trigger the deserialization of entities, can be used to trigger XXE attacks.

Exploit-Db

idEDB-ID:47770
last seen2019-12-11
modified2019-12-11
published2019-12-11
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/47770
titleApache Olingo OData 4.0 - XML External Entity Injection

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/155619/CSNC-2009-025.txt
idPACKETSTORM:155619
last seen2019-12-12
published2019-12-10
reporterArchibald Haddock
sourcehttps://packetstormsecurity.com/files/155619/Apache-Olingo-OData-4.6.x-XML-Injection.html
titleApache Olingo OData 4.6.x XML Injection