PT-2018-8450 · Eclipse · Eclipse Ide+1

Alon Boxiner

+3

·

Published

2018-04-20

·

Updated

2018-05-22

·

CVE-2017-8315

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Eclipse XML parser for the Eclipse IDE versions 2017.2.5 and earlier
Description The Eclipse XML parser for the Eclipse IDE was found vulnerable to an XML External Entity attack. An attacker can exploit this issue by implementing malicious code on the Androidmanifest.xml file.
Recommendations For Eclipse XML parser for the Eclipse IDE versions 2017.2.5 and earlier, update to a version later than 2017.2.5 to resolve the issue.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8315

Affected Products

Eclipse Ide
Eclipse Xml Parser