Cross Site Scripting Vulnerability in Eclipse Memory Analyzer
CVE-2019-17634
9CRITICAL
What is CVE-2019-17634?
Eclipse Memory Analyzer versions prior to 1.9.1 are vulnerable to a cross site scripting (XSS) flaw when generating HTML reports from potentially malicious heap dumps. Users must download and open a crafted heap dump, which could originate from compromised applications or malicious data inputs. When the report is generated and accessed either via the Memory Analyzer GUI or in batch mode through a web browser, the XSS vulnerability can be exploited, potentially allowing execution of unauthorized code on the local system.
Affected Version(s)
Eclipse Memory Analyzer All versions prior to version 1.9.2
References
CVSS V3.1
Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks to Iassen Minov for reporting the issue.