Description
In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit
document type definition (DTD) references to external entities.
This means that if a user chooses to use a malicious report definition XML file containing an external entity reference
to generate a report then Eclipse Memory Analyzer may access external files or URLs defined via a DTD in the report definition.
Published: 2023-12-11
Score: 2.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Workaround

A workaround for Eclipse Memory Analyzer 1.14.0 and earlier is to run MAT with the following system properties set in MemoryAnalyzer.ini -Djavax.xml.accessExternalSchema= -Djavax.xml.accessExternalDTD=

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-58442 In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit document type definition (DTD) references to external entities. This means that if a user chooses to use a malicious report definition XML file containing an external entity reference to generate a report then Eclipse Memory Analyzer may access external files or URLs defined via a DTD in the report definition.
History

No history.

Subscriptions

Eclipse Memory Analyzer
cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2024-08-02T08:21:17.798Z

Reserved: 2023-11-17T16:32:44.668Z

Link: CVE-2023-6194

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-12-11T14:15:31.847

Modified: 2024-11-21T08:43:19.773

Link: CVE-2023-6194

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses