CVE-2020-27225: High severity Eclipse Platform vulnerability
Published Mar 9, 2021
·Updated
In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to the local help web server, allowing an unauthenticated local attacker to issue active help commands to the associated Eclipse Platform process or Eclipse Rich Client Platform process.
Affected Software
2 affected components
Eclipse Platform<=4.18
IBM InfoSphere Data Architect<=9.2.1
Remediation
Patch Available
Event History
Mar 9, 2021
CVE Published
via MITRE·06:15 PM
Data Sourced
via MITRE·06:15 PM
DescriptionWeakness
Mar 4, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-27225?
CVE-2020-27225 is classified as a medium severity vulnerability.
2
How do I fix CVE-2020-27225?
To mitigate CVE-2020-27225, upgrade to a version of the Eclipse Platform later than 4.18.
3
Who is affected by CVE-2020-27225?
Users of Eclipse Platform versions 4.18 and earlier are affected by CVE-2020-27225.
4
What type of attacks can exploit CVE-2020-27225?
CVE-2020-27225 can be exploited by unauthenticated local attackers to issue active help commands.
5
What component of Eclipse Platform is vulnerable in CVE-2020-27225?
The Help Subsystem of the Eclipse Platform is the vulnerable component in CVE-2020-27225.