High severity7.1NVD Advisory· Published Jul 15, 2020· Updated Jun 17, 2026
CVE-2019-17637
CVE-2019-17637
Description
In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:eclipse:web_tools_platform:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:eclipse:web_tools_platform:*:*:*:*:*:*:*:*range: >=1.0,<=3.18
- (no CPE)range: <=3.18
- (no CPE)range: 1.0 to 3.18
Patches
Vulnerability mechanics
References
2- bugs.eclipse.org/bugs/show_bug.cginvdExploitIssue TrackingPatchVendor Advisory
- lists.debian.org/debian-lts-announce/2020/10/msg00016.htmlnvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.