PT-2024-3486 · Eclipse · Eclipse Target Management

Song

+2

·

Published

2024-01-19

·

Updated

2024-04-26

·

CVE-2024-0740

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Eclipse Target Management: Terminal and Remote System Explorer (RSE) versions <= 4.5.400
Description The issue exists due to the lack of measures to neutralize special elements used in operating system commands. This allows a remote attacker to execute arbitrary code without requiring authentication.
Recommendations For versions <= 4.5.400, update to a version included in Eclipse IDE 2024-03 or later to resolve the issue. As a temporary workaround, consider restricting access to the Terminal and Remote System Explorer (RSE) until a patch is applied.

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-03787
CVE-2024-0740

Affected Products

Eclipse Target Management