XML External Entity injection in Eclipse IDE for Java - CVE-2023-4218

 

XML External Entity injection in Eclipse IDE for Java - CVE-2023-4218

Published: February 26, 2024


Vulnerability identifier: #VU86800
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-4218
CWE-ID: CWE-611
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to some files with xml content are parsed vulnerable against all sorts of XXE attacks. A local user can trick the victim into opening a specially crafted XML code and view contents of arbitrary files on the system or initiate requests to external systems.


Affected software

Eclipse IDE for Java
Integration Bus for z/OS
IBM Enterprise Records
Engineering Test Management
webMethods BPM
Installation Manager
Packaging Utility
TPF Toolkit
Robotic Process Automation for Cloud Pak
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Package Hub 15
Development Tools Module
openSUSE Leap
IBM Concert Software
IBM Intelligent Operations Center
IBM Business Automation Workflow
IBM Maximo Application Suite - Manage Component
IBM MQ
IBM Robotic Process Automation
tycho-bootstrap
tycho-javadoc
tycho
eclipse-emf-runtime
eclipse-emf-xsd
eclipse-emf-sdk
eclipse-emf-core-bootstrap
eclipse-emf-core
maven-surefire-report-plugin
maven-surefire-provider-junit5-javadoc
maven-surefire-plugins-javadoc
maven-surefire-report-plugin-bootstrap
maven-surefire-provider-testng
maven-surefire-provider-junit
maven-surefire-javadoc
maven-surefire-plugin
maven-surefire-plugin-bootstrap
maven-surefire
maven-failsafe-plugin
maven-surefire-report-parser
maven-failsafe-plugin-bootstrap
maven-surefire-provider-junit5
eclipse-pde
eclipse-debugsource
eclipse-platform-debuginfo
eclipse-p2-discovery
eclipse-debuginfo
eclipse-swt-debuginfo
eclipse-jdt
eclipse-contributor-tools
eclipse-swt
eclipse-equinox-osgi
eclipse-platform
eclipse-equinox-osgi-bootstrap
eclipse-swt-bootstrap
eclipse-bootstrap-debuginfo
eclipse-jdt-bootstrap
eclipse-p2-discovery-bootstrap
eclipse-swt-bootstrap-debuginfo
eclipse-pde-bootstrap
eclipse-platform-bootstrap
eclipse-platform-bootstrap-debuginfo
eclipse-bootstrap-debugsource
Operational Decision Manager
IBM App Connect Enterprise

How to mitigate CVE-2023-4218

Install updates from vendor's website.

IBM Concert Software - update to 2.2.0
IBM Enterprise Records - update to 5.2.1.9
Engineering Test Management - update to 7.1.0.0.6
webMethods BPM - update to 12.1 Fix 1
IBM Business Automation Workflow - update to 24.0.0-IF002
tycho-bootstrap - update to 1.6.0-150200.4.9.2
tycho-javadoc - update to 1.6.0-150200.4.9.5
tycho - update to 1.6.0-150200.4.9.5
Installation Manager - update to 1.10.1.1
Packaging Utility - update to 1.10.1.1
eclipse-emf-runtime - update to 2.22.0-150200.4.9.3
eclipse-emf-xsd - update to 2.22.0-150200.4.9.3
eclipse-emf-sdk - update to 2.22.0-150200.4.9.3
eclipse-emf-core-bootstrap - update to 2.22.0-150200.4.9.3
eclipse-emf-core - update to 2.22.0-150200.4.9.3
maven-surefire-report-plugin - update to 2.22.2-150200.3.9.9.1
maven-surefire-provider-junit5-javadoc - update to 2.22.2-150200.3.9.9.1
maven-surefire-plugins-javadoc - update to 2.22.2-150200.3.9.9.1
maven-surefire-report-plugin-bootstrap - update to 2.22.2-150200.3.9.9.1
maven-surefire-provider-testng - update to 2.22.2-150200.3.9.9.1
maven-surefire-provider-junit - update to 2.22.2-150200.3.9.9.1
maven-surefire-javadoc - update to 2.22.2-150200.3.9.9.1
maven-surefire-plugin - update to 2.22.2-150200.3.9.9.1
maven-surefire-plugin-bootstrap - update to 2.22.2-150200.3.9.9.1
maven-surefire - update to 2.22.2-150200.3.9.9.1
maven-failsafe-plugin - update to 2.22.2-150200.3.9.9.1
maven-surefire-report-parser - update to 2.22.2-150200.3.9.9.1
maven-failsafe-plugin-bootstrap - update to 2.22.2-150200.3.9.9.1
maven-surefire-provider-junit5 - update to 2.22.2-150200.3.9.9.1
TPF Toolkit - update to 4.6 FP18
eclipse-pde - update to 4.15-150200.4.16.4
eclipse-debugsource - update to 4.15-150200.4.16.4
eclipse-platform-debuginfo - update to 4.15-150200.4.16.4
eclipse-p2-discovery - update to 4.15-150200.4.16.4
eclipse-debuginfo - update to 4.15-150200.4.16.4
eclipse-swt-debuginfo - update to 4.15-150200.4.16.4
eclipse-jdt - update to 4.15-150200.4.16.4
eclipse-contributor-tools - update to 4.15-150200.4.16.4
eclipse-swt - update to 4.15-150200.4.16.4
eclipse-equinox-osgi - update to 4.15-150200.4.16.4
eclipse-platform - update to 4.15-150200.4.16.4
eclipse-equinox-osgi-bootstrap - update to 4.15-150200.4.16.5
eclipse-swt-bootstrap - update to 4.15-150200.4.16.5
eclipse-bootstrap-debuginfo - update to 4.15-150200.4.16.5
eclipse-jdt-bootstrap - update to 4.15-150200.4.16.5
eclipse-p2-discovery-bootstrap - update to 4.15-150200.4.16.5
eclipse-swt-bootstrap-debuginfo - update to 4.15-150200.4.16.5
eclipse-pde-bootstrap - update to 4.15-150200.4.16.5
eclipse-platform-bootstrap - update to 4.15-150200.4.16.5
eclipse-platform-bootstrap-debuginfo - update to 4.15-150200.4.16.5
eclipse-bootstrap-debugsource - update to 4.15-150200.4.16.5
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.29, 8.7.23, 9.0.16, 9.1.2
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 32, 8.11.1 Interim fix 25, 8.12.0.1 Interim fix 10
IBM MQ - addressed in versions 9.0.0.23, 9.1.0.20, 9.2.0.22, 9.3.5
IBM App Connect Enterprise - addressed in versions 11.0.0.24, 12.0.11.1
IBM Robotic Process Automation - addressed in versions 21.0.7.15, 23.0.16
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.15, 23.0.16

External References

Related Security Bulletins