CWE-611
1,268 CVEs • Abstraction: Base
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVEs (1,268)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM QRadar Network Security 5.4 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory...Show more |
2Automatedlogic Carrier3Automatedlogic Webctrl I VuSitescan WebMay 13, 2026 Aug 31, 2017 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 An XXE issue was discovered in Automated Logic Corporation (ALC) Liebert SiteScan Web Version 6.5 and prior, ALC WebCTRL Version 6.5 and prior, and Carrier i-Vu Version 6.5 and prior. An attacker could enter malicious in...Show more |
2Ocpfoundation Siemens4Local Discovery Server Simatic Pcs7Ua .net+1 moreMay 13, 2026 Aug 30, 2017 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Among the affected products are Siemens SIMATIC PCS7 (All versions V8.1 a...Show more |
Adobe Digital Editions 4.5.4 and earlier has a security bypass vulnerability. |
The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera Parser which expands XML entities by default which represents...Show more |
IBM Sterling B2B Integrator 5.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consum...Show more |
XML External Entity (XXE) vulnerability in Apache Wink 1.1.1 and earlier allows remote attackers to read arbitrary files or cause a denial of service via a crafted XML document. |
XML external entity (XXE) processing vulnerability in Trend Micro Control Manager 6.0, if exploited, could lead to information disclosure. Formerly ZDI-CAN-4706. |
1Ibm 2Sterling B2b Integrator Sterling File GatewayMay 13, 2026 Aug 2, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling File Gateway 2.1 and 2.2 allows remote attackers to read arbitrary files via a crafted XML data. |
1Ibm 1Infosphere Information Server May 13, 2026 Aug 2, 2017 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive informa...Show more |
3Debian Libexpat ProjectPython3Debian Linux LibexpatPythonMay 13, 2026 Jul 25, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD. |
1Sap 1Netweaver Application Server Java May 13, 2026 Jul 25, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD...Show more |
IBM Tivoli Endpoint Manager is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory res...Show more |
In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string, which allows for XXE attacks in all scripts which use this method to...Show more |
Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0. |
xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information disclosure or denial of service |
LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents. |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 13, 2026 Jul 11, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Windows System Information Console in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an...Show more |
1Microsoft 6Windows 10 Windows 7Windows 8.1+3 moreMay 13, 2026 Jul 11, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Windows Performance Monitor in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an informa...Show more |
IBM Security Guardium 10.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memo...Show more |