CWE-611
1,244 CVEs • Abstraction: Base
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVEs (1,244)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An exploitable unauthenticated XML external injection vulnerability was identified in FocalScope v2416. A unauthenticated attacker could submit a specially crafted web request to FocalScope's server that could cause an X...Show more |
Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor. |
1Redhat 1Jboss Enterprise Application Platform Nov 21, 2024 Jul 27, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to cause DoS, SSRF, or information disclosure if they are able t...Show more |
1Redhat 3Decision Manager Jboss Bpm SuiteJbpmNov 21, 2024 Jul 26, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user runnin...Show more |
1Selinc 1Acselerator Architect Nov 21, 2024 Jul 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SEL AcSELerator Architect version 2.2.24.0 and prior allows unsanitized input to be passed to the XML parser, which may allow disclosure and retrieval of arbitrary data, arbitrary code execution (in certain situations on...Show more |
XML external entity (XXE) vulnerability in java/org/jasig/cas/util/SamlUtils.java in Jasig CAS server before 3.4.12.1 and 3.5.x before 3.5.2.1, when Google Accounts Integration is enabled, allows remote unauthenticated u...Show more |
XMLReader.php in PHPOffice Common before 0.2.9 allows XXE. |
1Zohocorp 1Manageengine Applications Manager Nov 21, 2024 Jul 13, 2018 N/A· v4 4.9 MEDIUM· v3 6.8 MEDIUM· v2 ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /register.do page (most likely limited to administrator), to browse the filesystem and read the system fi...Show more |
EpubCheck 4.0.1 does not properly restrict resolving external entities when parsing XML in EPUB files during validation. An attacker who supplies a specially crafted EPUB file may be able to exploit this behavior to read...Show more |
1Hp 1Fortify Software Security Center Nov 21, 2024 Jul 12, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) att...Show more |
ONOS ONOS controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in onos\drivers\utilities\src\main\java\org\onosproject\drivers\utilities\XmlConfigParser.java loadxml() that can result...Show more |
ONOS ONOS Controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in providers/netconf/alarm/src/main/java/org/onosproject/provider/netconf/alarm/NetconfAlarmTranslator.java that can resu...Show more |
WXPayUtil in WeChat Pay Java SDK allows XXE attacks involving a merchant notification URL. |
1Ibm 2Content Foundation Filenet Content ManagerNov 21, 2024 Jul 6, 2018 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 IBM FileNet Content Manager, IBM Content Foundation, and IBM Case Foundation Administration Console for Content Platform Engine (ACCE) 5.2.1 and 5.5.0 are vulnerable to a XML External Entity Injection (XXE) attack when p...Show more |
2Apache Netapp3Snapcenter SolrStorage Automation StoreNov 21, 2024 Jul 5, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entity expansion (XXE) in Solr config files (currency.xml, enumsConfig.xml referred from schema.xml, TIKA parsecontext config...Show more |
XML External Entity (XXE) vulnerability in the web service in Dialogic PowerMedia XMS before 3.5 SU2 allows remote attackers to read arbitrary files or cause a denial of service (resource consumption). |
1Schneider Electric 1Somachine Basic Nov 21, 2024 Jul 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Schneider Electric SoMachine Basic prior to v1.6 SP1 suffers from an XML External Entity (XXE) vulnerability using the DTD parameter entities technique resulting in disclosure and retrieval of arbitrary data on the affec...Show more |
1Redhat 1Jboss Enterprise Application Platform Nov 21, 2024 Jun 27, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw to cause remote code execution if they are able to provide XSLT content...Show more |
Umlet version < 14.3 contains a XML External Entity (XXE) vulnerability in File parsing that can result in disclosure of confidential data, denial of service, server side request forgery. This attack appear to be exploit...Show more |
Triplea version <= 1.9.0.0.10291 contains a XML External Entity (XXE) vulnerability in Importing game data that can result in Possible information disclosure, server-side request forgery, or remote code execution. This a...Show more |