{"api_version":"1","generated_at":"2026-07-24T20:01:36+00:00","cve":"CVE-2020-27225","urls":{"html":"https://cve.report/CVE-2020-27225","api":"https://cve.report/api/cve/CVE-2020-27225.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-27225","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-27225"},"summary":{"title":"CVE-2020-27225","description":"In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to the local help web server, allowing an unauthenticated local attacker to issue active help commands to the associated Eclipse Platform process or Eclipse Rich Client Platform process.","state":"PUBLIC","assigner":"security@eclipse.org","published_at":"2021-03-09 19:15:00","updated_at":"2021-03-18 18:22:00"},"problem_types":["CWE-306"],"metrics":[],"references":[{"url":"https://bugs.eclipse.org/bugs/show_bug.cgi?id=569855","name":"https://bugs.eclipse.org/bugs/show_bug.cgi?id=569855","refsource":"CONFIRM","tags":["Exploit","Issue Tracking","Patch","Vendor Advisory"],"title":"569855 – (CVE-2020-27225) Vulnerability in Eclipse livehelp.","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-27225","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-27225","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"27225","vulnerable":"1","versionEndIncluding":"4.18","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"eclipse","cpe5":"platform","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2020-27225","qid":"376108","title":"IBM MQ Arbitrary Code Execution Vulnerability (6513983)"},{"cve":"CVE-2020-27225","qid":"750289","title":"OpenSUSE Security Update for eclipse (openSUSE-SU-2021:0485-1)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2020-27225","ASSIGNER":"security@eclipse.org","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"The Eclipse Foundation","product":{"product_data":[{"product_name":"Eclipse Platform","version":{"version_data":[{"version_affected":"<=","version_value":"4.18"}]}}]}}]}},"description":{"description_data":[{"lang":"eng","value":"In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to the local help web server, allowing an unauthenticated local attacker to issue active help commands to the associated Eclipse Platform process or Eclipse Rich Client Platform process."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-306: Missing Authentication for Critical Function"}]}]},"references":{"reference_data":[{"name":"https://bugs.eclipse.org/bugs/show_bug.cgi?id=569855","refsource":"CONFIRM","url":"https://bugs.eclipse.org/bugs/show_bug.cgi?id=569855"}]}},"nvd":{"publishedDate":"2021-03-09 19:15:00","lastModifiedDate":"2021-03-18 18:22:00","problem_types":["CWE-306"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":4.6},"severity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:eclipse:platform:*:*:*:*:*:*:*:*","versionEndIncluding":"4.18","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"27225","Ordinal":"188659","Title":"CVE-2020-27225","CVE":"CVE-2020-27225","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"27225","Ordinal":"1","NoteData":"In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to the local help web server, allowing an unauthenticated local attacker to issue active help commands to the associated Eclipse Platform process or Eclipse Rich Client Platform process.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"27225","Ordinal":"2","NoteData":"2021-03-09","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"27225","Ordinal":"3","NoteData":"2021-03-09","Type":"Other","Title":"Modified"}]}}}