Security Advisory
CVE-2019-17554
5.5
MEDIUM
Vulnerability Description
The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Request with content type "application/xml", which trigger the deserialization of entities, can be used to trigger XXE attacks.
Published Date
December 4, 2019
Official Source
NIST NVD Advisory