In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit
document type definition (DTD) references to external entities.
This means that if a user chooses to use a malicious report definition XML file containing an external entity reference
to generate a report then Eclipse Memory Analyzer may access external files or URLs defined via a DTD in the report definition.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-58442 In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit document type definition (DTD) references to external entities. This means that if a user chooses to use a malicious report definition XML file containing an external entity reference to generate a report then Eclipse Memory Analyzer may access external files or URLs defined via a DTD in the report definition.
Fixes

Solution

No solution given by the vendor.


Workaround

A workaround for Eclipse Memory Analyzer 1.14.0 and earlier is to run MAT with the following system properties set in MemoryAnalyzer.ini -Djavax.xml.accessExternalSchema= -Djavax.xml.accessExternalDTD=

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2024-08-02T08:21:17.798Z

Reserved: 2023-11-17T16:32:44.668Z

Link: CVE-2023-6194

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-12-11T14:15:31.847

Modified: 2024-11-21T08:43:19.773

Link: CVE-2023-6194

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.