Skip to content

[FP]: Incorrect CVE Detection – CVE-2010-4647 #8174

@MohammedSuhaibT

Description

@MohammedSuhaibT

Package URl

pkg:maven/org.eclipse.angus/[email protected]

CPE

cpe:2.3:a:eclipse:eclipse_ide::::::::

CVE

CVE-2010-4647

ODC Integration

None

ODC Version

12.1.3

Description

CVE-2010-4647 describes XSS vulnerabilities in the Help Server of Eclipse IDE versions before 3.6.2, affecting JSP pages such as help/index.jsp and help/advanced/content.jsp.

Our Application does not use the Eclipse IDE or its Help Server components.
The flagged dependency (angus-activation.jar 2.0.2) is unrelated and not impacted.
The application uses modern JAXB and activation libraries only, which are not vulnerable.

This is a false positive due to incorrect association of the CVE with the scanned jar.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions