PT-2019-15206 · Apache · Apache Olingo
Artem Smotrakov
·
Publicado
2019-12-04
·
Atualizado
2020-02-04
·
CVE-2019-17556
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache Olingo versions 4.0.0 through 4.6.0
Description
The issue concerns the AbstractService class in Apache Olingo, which uses ObjectInputStream without checking the classes being deserialized. This could allow an attacker to execute malicious code if they can provide malicious metadata to the class.
Recommendations
For Apache Olingo versions 4.0.0 through 4.6.0, consider restricting access to the AbstractService class until a patch is available. As a temporary workaround, avoid using the ObjectInputStream functionality in the AbstractService class to minimize the risk of exploitation.
Correção
Deserialization of Untrusted Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Olingo