In all versions of Eclipse Web Tools Platform through release...
Vulnerability Description
In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-17637
Credits & Attribution
No credits recorded in the NVD database.
References
More from The Eclipse Foundation
View All →Affected Vendor
The Eclipse Foundation
View all reports →