← Back

CVE-2019-17556

nvd nist
Published: Dec 4, 2019Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being deserialized. If an attacker can feed malicious metadata to the class, then it may result in running attacker's code in the worse case.

Affected (1)

Products: Apache: Olingo
1 product
Olingo
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 4.0.0 to 4.6.0

Timeline

No history available yet.