XML External Entity injection in Eclipse IDE for Java - CVE-2023-4218
Published: February 26, 2024
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to some files with xml content are parsed vulnerable against all sorts of XXE attacks. A local user can trick the victim into opening a specially crafted XML code and view contents of arbitrary files on the system or initiate requests to external systems.
Affected software
Integration Bus for z/OS
IBM Enterprise Records
Engineering Test Management
webMethods BPM
Installation Manager
Packaging Utility
TPF Toolkit
Robotic Process Automation for Cloud Pak
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Package Hub 15
Development Tools Module
openSUSE Leap
IBM Concert Software
IBM Intelligent Operations Center
IBM Business Automation Workflow
IBM Maximo Application Suite - Manage Component
IBM MQ
IBM Robotic Process Automation
tycho-bootstrap
tycho-javadoc
tycho
eclipse-emf-runtime
eclipse-emf-xsd
eclipse-emf-sdk
eclipse-emf-core-bootstrap
eclipse-emf-core
maven-surefire-report-plugin
maven-surefire-provider-junit5-javadoc
maven-surefire-plugins-javadoc
maven-surefire-report-plugin-bootstrap
maven-surefire-provider-testng
maven-surefire-provider-junit
maven-surefire-javadoc
maven-surefire-plugin
maven-surefire-plugin-bootstrap
maven-surefire
maven-failsafe-plugin
maven-surefire-report-parser
maven-failsafe-plugin-bootstrap
maven-surefire-provider-junit5
eclipse-pde
eclipse-debugsource
eclipse-platform-debuginfo
eclipse-p2-discovery
eclipse-debuginfo
eclipse-swt-debuginfo
eclipse-jdt
eclipse-contributor-tools
eclipse-swt
eclipse-equinox-osgi
eclipse-platform
eclipse-equinox-osgi-bootstrap
eclipse-swt-bootstrap
eclipse-bootstrap-debuginfo
eclipse-jdt-bootstrap
eclipse-p2-discovery-bootstrap
eclipse-swt-bootstrap-debuginfo
eclipse-pde-bootstrap
eclipse-platform-bootstrap
eclipse-platform-bootstrap-debuginfo
eclipse-bootstrap-debugsource
Operational Decision Manager
IBM App Connect Enterprise
How to mitigate CVE-2023-4218
IBM Enterprise Records - update to 5.2.1.9
Engineering Test Management - update to 7.1.0.0.6
webMethods BPM - update to 12.1 Fix 1
IBM Business Automation Workflow - update to 24.0.0-IF002
tycho-bootstrap - update to 1.6.0-150200.4.9.2
tycho-javadoc - update to 1.6.0-150200.4.9.5
tycho - update to 1.6.0-150200.4.9.5
Installation Manager - update to 1.10.1.1
Packaging Utility - update to 1.10.1.1
eclipse-emf-runtime - update to 2.22.0-150200.4.9.3
eclipse-emf-xsd - update to 2.22.0-150200.4.9.3
eclipse-emf-sdk - update to 2.22.0-150200.4.9.3
eclipse-emf-core-bootstrap - update to 2.22.0-150200.4.9.3
eclipse-emf-core - update to 2.22.0-150200.4.9.3
maven-surefire-report-plugin - update to 2.22.2-150200.3.9.9.1
maven-surefire-provider-junit5-javadoc - update to 2.22.2-150200.3.9.9.1
maven-surefire-plugins-javadoc - update to 2.22.2-150200.3.9.9.1
maven-surefire-report-plugin-bootstrap - update to 2.22.2-150200.3.9.9.1
maven-surefire-provider-testng - update to 2.22.2-150200.3.9.9.1
maven-surefire-provider-junit - update to 2.22.2-150200.3.9.9.1
maven-surefire-javadoc - update to 2.22.2-150200.3.9.9.1
maven-surefire-plugin - update to 2.22.2-150200.3.9.9.1
maven-surefire-plugin-bootstrap - update to 2.22.2-150200.3.9.9.1
maven-surefire - update to 2.22.2-150200.3.9.9.1
maven-failsafe-plugin - update to 2.22.2-150200.3.9.9.1
maven-surefire-report-parser - update to 2.22.2-150200.3.9.9.1
maven-failsafe-plugin-bootstrap - update to 2.22.2-150200.3.9.9.1
maven-surefire-provider-junit5 - update to 2.22.2-150200.3.9.9.1
TPF Toolkit - update to 4.6 FP18
eclipse-pde - update to 4.15-150200.4.16.4
eclipse-debugsource - update to 4.15-150200.4.16.4
eclipse-platform-debuginfo - update to 4.15-150200.4.16.4
eclipse-p2-discovery - update to 4.15-150200.4.16.4
eclipse-debuginfo - update to 4.15-150200.4.16.4
eclipse-swt-debuginfo - update to 4.15-150200.4.16.4
eclipse-jdt - update to 4.15-150200.4.16.4
eclipse-contributor-tools - update to 4.15-150200.4.16.4
eclipse-swt - update to 4.15-150200.4.16.4
eclipse-equinox-osgi - update to 4.15-150200.4.16.4
eclipse-platform - update to 4.15-150200.4.16.4
eclipse-equinox-osgi-bootstrap - update to 4.15-150200.4.16.5
eclipse-swt-bootstrap - update to 4.15-150200.4.16.5
eclipse-bootstrap-debuginfo - update to 4.15-150200.4.16.5
eclipse-jdt-bootstrap - update to 4.15-150200.4.16.5
eclipse-p2-discovery-bootstrap - update to 4.15-150200.4.16.5
eclipse-swt-bootstrap-debuginfo - update to 4.15-150200.4.16.5
eclipse-pde-bootstrap - update to 4.15-150200.4.16.5
eclipse-platform-bootstrap - update to 4.15-150200.4.16.5
eclipse-platform-bootstrap-debuginfo - update to 4.15-150200.4.16.5
eclipse-bootstrap-debugsource - update to 4.15-150200.4.16.5
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.29, 8.7.23, 9.0.16, 9.1.2
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 32, 8.11.1 Interim fix 25, 8.12.0.1 Interim fix 10
IBM MQ - addressed in versions 9.0.0.23, 9.1.0.20, 9.2.0.22, 9.3.5
IBM App Connect Enterprise - addressed in versions 11.0.0.24, 12.0.11.1
IBM Robotic Process Automation - addressed in versions 21.0.7.15, 23.0.16
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.15, 23.0.16
External References
- https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/8
- https://github.com/eclipse-pde/eclipse.pde/pull/632/
- https://github.com/eclipse-pde/eclipse.pde/pull/667/
- https://github.com/eclipse-platform/eclipse.platform/pull/761
- https://github.com/eclipse-platform/eclipse.platform.releng.buildtools/pull/45
- https://github.com/eclipse-platform/eclipse.platform.ui/commit/f243cf0a28785b89b7c50bf4e1cce48a917d89bd
- https://github.com/eclipse-jdt/eclipse.jdt.ui/commit/13675b1f8a74f47de4da89ed0ded6af7c21dfbec
- https://github.com/eclipse-jdt/eclipse.jdt.core/commit/38dd2a878f45cdb3d8d52090f1d6d1b532fd4c4d
- https://github.com/eclipse-emf/org.eclipse.emf/issues/10
- https://github.com/eclipse-platform/eclipse.platform.swt/commit/bf71db5ddcb967c0863dad4745367b54f49e06ba
- https://github.com/eclipse-cdt/cdt/commit/c7169b3186d2fef20f97467c3e2ad78e2943ed1b
Related Security Bulletins
- XML External Entity injection in IBM App Connect Enterprise and IBM Integration Bus for z/OS
- Multiple vulnerabilities in IBM MQ
- Multiple vulnerabilities in IBM Intelligent Operations Center (IOC)
- SUSE update for eclipse, maven-surefire, tycho
- Multiple vulnerabilities in TPF Toolkit
- Multiple vulnerabilities in IBM Robotic Process Automation
- Multiple vulnerabilities in IBM Operational Decision Manager
- Multiple vulnerabilities in IBM Installation Manager and IBM Packaging Utility
- IBM Business Automation Workflow update for Eclipse IDE
- IBM Maximo Application Suite - Manage Component update for Eclipse IDE
- Multiple vulnerabilities in IBM Concert Software
- IBM Engineering Test Management update for Eclipse IDE
- IBM Enterprise Records update for Eclipse IDE
- IBM webMethods BPM update for Eclipse IDE