CVE-2023-6194: XEE
In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit document type definition (DTD) references to external entities. This means that if a user chooses to use a malicious report definition XML file containing an external entity reference to generate a report then Eclipse Memory Analyzer may access external files or URLs defined via a DTD in the report definition.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6194?
CVE-2023-6194 has a medium severity rating due to the potential for XML external entity injection.
How do I fix CVE-2023-6194?
To fix CVE-2023-6194, update Eclipse Memory Analyzer to version 1.15.0 or later.
Which versions of Eclipse Memory Analyzer are affected by CVE-2023-6194?
Eclipse Memory Analyzer versions 0.7 through 1.14.0 are affected by CVE-2023-6194.
What vulnerability type is CVE-2023-6194 associated with?
CVE-2023-6194 is associated with XML external entity (XXE) vulnerabilities.
Can CVE-2023-6194 be exploited through user action?
Yes, CVE-2023-6194 can be exploited if a user opens a malicious report definition XML file.