External Entity Injection Vulnerability in Eclipse Memory Analyzer
CVE-2023-6194
2.8LOW
What is CVE-2023-6194?
In Eclipse Memory Analyzer versions ranging from 0.7 to 1.14.0, a vulnerability exists that permits report definition XML files to include document type definition (DTD) references, leading to potential external entity injections. This issue can be exploited if a user mistakenly utilizes a maliciously crafted XML file containing DTD references, allowing the application to inadvertently access external files or URLs defined in that DTD, thereby posing a significant risk to the integrity and confidentiality of sensitive data.
Affected Version(s)
Eclipse Memory Analyzer (tools.mat) 0.7 <= 1.14.0