9.8
CVSSv3

CVE-2019-17556

Published: 04/12/2019 Updated: 13/12/2019
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 895
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being deserialized. If an attacker can feed malicious metadata to the class, then it may result in running attacker's code in the worse case.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache olingo

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2019-17556: Olingo: Deserialization vulnerability <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: mibo &lt;mi ...