{"api_version":"1","generated_at":"2026-07-23T12:42:18+00:00","cve":"CVE-2017-8315","urls":{"html":"https://cve.report/CVE-2017-8315","api":"https://cve.report/api/cve/CVE-2017-8315.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-8315","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-8315"},"summary":{"title":"CVE-2017-8315","description":"Eclipse XML parser for the Eclipse IDE versions 2017.2.5 and earlier was found vulnerable to an XML External Entity attack. An attacker can exploit the vulnerability by implementing malicious code on Androidmanifest.xml.","state":"PUBLIC","assigner":"cve@checkpoint.com","published_at":"2018-04-20 19:29:00","updated_at":"2018-05-22 15:33:00"},"problem_types":["CWE-611"],"metrics":[],"references":[{"url":"https://bugs.eclipse.org/bugs/show_bug.cgi?id=519169","name":"https://bugs.eclipse.org/bugs/show_bug.cgi?id=519169","refsource":"CONFIRM","tags":["Permissions Required","Vendor Advisory"],"title":"519169 – XXE Vulnerability found in Eclipse","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://research.checkpoint.com/parsedroid-targeting-android-development-research-community/","name":"https://research.checkpoint.com/parsedroid-targeting-android-development-research-community/","refsource":"MISC","tags":["Exploit","Technical Description","Third Party Advisory"],"title":"ParseDroid: Targeting The Android Development & Research Community - Check Point Research","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-8315","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-8315","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"8315","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"eclipse","cpe5":"ide","cpe6":"2017.2.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"8315","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"eclipse","cpe5":"ide","cpe6":"2017.2.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@checkpoint.com","DATE_PUBLIC":"2017-12-04T00:00:00","ID":"CVE-2017-8315","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Eclipse","version":{"version_data":[{"version_value":"All version lower or equal to 2017.2.5"}]}}]},"vendor_name":"Check Point Software Technologies Ltd."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Eclipse XML parser for the Eclipse IDE versions 2017.2.5 and earlier was found vulnerable to an XML External Entity attack. An attacker can exploit the vulnerability by implementing malicious code on Androidmanifest.xml."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Local Privilege Escalation"}]}]},"references":{"reference_data":[{"name":"https://bugs.eclipse.org/bugs/show_bug.cgi?id=519169","refsource":"CONFIRM","url":"https://bugs.eclipse.org/bugs/show_bug.cgi?id=519169"},{"name":"https://research.checkpoint.com/parsedroid-targeting-android-development-research-community/","refsource":"MISC","url":"https://research.checkpoint.com/parsedroid-targeting-android-development-research-community/"}]}},"nvd":{"publishedDate":"2018-04-20 19:29:00","lastModifiedDate":"2018-05-22 15:33:00","problem_types":["CWE-611"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.8},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.9,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:eclipse:ide:2017.2.5:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"8315","Ordinal":"105210","Title":"CVE-2017-8315","CVE":"CVE-2017-8315","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"8315","Ordinal":"1","NoteData":"Eclipse XML parser for the Eclipse IDE versions 2017.2.5 and earlier was found vulnerable to an XML External Entity attack. An attacker can exploit the vulnerability by implementing malicious code on Androidmanifest.xml.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"8315","Ordinal":"2","NoteData":"2018-04-20","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"8315","Ordinal":"3","NoteData":"2018-04-20","Type":"Other","Title":"Modified"}]}}}