Cross Site Scripting Vulnerability in Eclipse Memory Analyzer
CVE-2019-17634

9CRITICAL

Key Information:

Vendor
CVE Published:
17 January 2020

What is CVE-2019-17634?

Eclipse Memory Analyzer versions prior to 1.9.1 are vulnerable to a cross site scripting (XSS) flaw when generating HTML reports from potentially malicious heap dumps. Users must download and open a crafted heap dump, which could originate from compromised applications or malicious data inputs. When the report is generated and accessed either via the Memory Analyzer GUI or in batch mode through a web browser, the XSS vulnerability can be exploited, potentially allowing execution of unauthorized code on the local system.

Affected Version(s)

Eclipse Memory Analyzer All versions prior to version 1.9.2

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks to Iassen Minov for reporting the issue.
.