First published: Mon Dec 11 2023(Updated: )
In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit document type definition (DTD) references to external entities. This means that if a user chooses to use a malicious report definition XML file containing an external entity reference to generate a report then Eclipse Memory Analyzer may access external files or URLs defined via a DTD in the report definition.
Credit: emo@eclipse.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse Memory Analyzer | >=0.7<=1.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6194 has a medium severity rating due to the potential for XML external entity injection.
To fix CVE-2023-6194, update Eclipse Memory Analyzer to version 1.15.0 or later.
Eclipse Memory Analyzer versions 0.7 through 1.14.0 are affected by CVE-2023-6194.
CVE-2023-6194 is associated with XML external entity (XXE) vulnerabilities.
Yes, CVE-2023-6194 can be exploited if a user opens a malicious report definition XML file.