CWE-611
1,268 CVEs • Abstraction: Base
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVEs (1,268)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redwood 1Sap Business Process Automation Nov 21, 2024 Mar 14, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SAP Business Process Automation (BPA) By Redwood does not sufficiently validate an XML document accepted from an untrusted source resulting in an XML External Entity (XXE) vulnerability. |
Spacewalk 2.6 contains an API which has an XXE flaw allowing for the disclosure of potentially sensitive information from the server. |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreApr 4, 2025 Mar 14, 2018 N/A· v4 3.1 LOW· v3 2.6 LOW· v2 Windows Remote Assistance in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows S...Show more |
I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_string) that can result in an attacker reading the contents of a file an...Show more |
textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial of service in context to the web server by exhausting server memory resources. This attack appear t...Show more |
2Debian Freeplane2Debian Linux FreeplaneNov 21, 2024 Mar 13, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 FreePlane version 1.5.9 and earlier contains a XML External Entity (XXE) vulnerability in XML Parser in mindmap loader that can result in stealing data from victim's machine. This attack appears to require the victim to...Show more |
The Upload File functionality in upload.jspa in Aurea Jive Jive-n 9.0.2.1 On-Premises allows for an XML External Entity attack through a crafted file, allowing attackers to read arbitrary files. |
1Ibm 1Infosphere Information Server Nov 21, 2024 Mar 12, 2018 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 XML external entity (XXE) vulnerability in IBM InfoSphere Information Governance Catalog 11.3 before 11.3.1.2 and 11.5 before 11.5.0.1 allows remote authenticated users to read arbitrary files or cause a denial of servic...Show more |
1Schneider Electric 20Ibp1110 1er Firmware Ibp219 1er FirmwareIbp319 1er Firmware+17 moreJun 17, 2026 Mar 9, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A XML external entity (XXE) vulnerability exists in the import.cgi of the web interface component of the Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67. |
1Ibm 1Financial Transaction Manager Nov 21, 2024 Mar 9, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 XML external entity (XXE) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-P...Show more |
1Cisco 1Secure Access Control Server Solution Engine Nov 21, 2024 Mar 8, 2018 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticated, remote attacker to gain read access to certain information in the affected sy...Show more |
1Cisco 1Secure Access Control Server Solution Engine Nov 21, 2024 Mar 8, 2018 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticated, remote attacker to gain read access to certain information in the affected sy...Show more |
The NetIQ Identity Manager Plugins before 4.6.1 contained various XML External XML Entity (XXE) handling flaws that could be used by attackers to leak information or cause denial of service attacks. |
In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView. |
1Microfocus 1Project And Portfolio Management Center Jun 17, 2026 Feb 22, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 XML External Entity (XXE) vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability can be exploited to allow XML External Entity (XXE) |
1Ibm 3Control Center Financial Transaction ManagerTransformation Extender AdvancedNov 21, 2024 Feb 21, 2018 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM Financial Transaction Manager 3.0.2, 3.0.3, 3.0.4, and 3.1.0, IBM Transformation Extender Advanced 9.0) is vulner...Show more |
XML external entity (XXE) vulnerability in IBM Forms Experience Builder 8.5, 8.5.1, and 8.6 allows remote authenticated users to obtain sensitive information via crafted XML data. IBM X-Force ID: 112088. |
3Debian GoogleXmlsoft3Android Debian LinuxLibxml2Dec 3, 2025 Feb 19, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Dependin...Show more |
1Hp 1Aruba Clearpass Policy Manager Nov 21, 2024 Feb 15, 2018 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 An arbitrary command execution vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found. |
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable. |