PT-2020-9930 · Eclipse · Eclipse Web Tools Platform

David Dworken

+1

·

Published

2020-07-15

·

Updated

2023-01-27

·

CVE-2019-17637

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Eclipse Web Tools Platform versions prior to 3.18 (2020-06)
Description The issue allows XML and DTD files referring to external entities to be exploited, sending the contents of local files to a remote server when edited or validated. This can occur even when external entity resolution is disabled in the user preferences.
Recommendations For Eclipse Web Tools Platform versions prior to 3.18 (2020-06), consider updating to a version newer than 3.18 (2020-06) to resolve the issue. As a temporary workaround, restrict the editing and validation of XML and DTD files that refer to external entities to minimize the risk of exploitation.

Exploit

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2019-17637
DLA-2404-1

Affected Products

Eclipse Web Tools Platform