CWE-611
1,268 CVEs • Abstraction: Base
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVEs (1,268)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Xoev 1Osci Transport Library May 13, 2026 Jun 30, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An XML External Entity (XXE) issue exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET), exploitable by sending a crafted standard-conforming OSCI message from...Show more |
IBM API Connect 5.0.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory...Show more |
1Cisco 2Evolved Programmable Network Manager Prime InfrastructureMay 13, 2026 Jun 26, 2017 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker read and write access to information stored...Show more |
XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obtain sensitive information via unspecified vectors. |
1Ibm 1Rational Rhapsody Design Manager May 13, 2026 Jun 8, 2017 N/A· v4 8.1 HIGH· v3 7.5 HIGH· v2 IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly...Show more |
1Ibm 1Cognos Business Intelligence May 13, 2026 Jun 7, 2017 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 IBM Cognos Business Intelligence 10.1 and 10.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote authenticated attacker could exploit this vul...Show more |
XML External Entity (XXE) vulnerability in Milton Webdav before 2.7.0.3. |
An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.1R1 may allow an authenticated user to read arbitrary files on the device. |
XXE vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Replication Manager before 8.5.2-00 allows authenticated remote users to read arbitrary files. |
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcellerator/exec/soap/vP.001sap0003.in_WCSX/com.sap.b1i.vplatform.runtime/IN...Show more |
2Pivotal Software Vmware2Spring Framework Spring FrameworkMay 13, 2026 May 25, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration...Show more |
1Sap 1Netweaver Application Server Java May 13, 2026 May 23, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via a crafted XML document in a request to irj/servlet/prt/portal/prtr...Show more |
IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memo...Show more |
1Schneider Electric 1Wonderware Historian Client May 13, 2026 May 19, 2017 N/A· v4 6.6 MEDIUM· v3 3.3 LOW· v2 An Improper XML Parser Configuration issue was discovered in Schneider Electric Wonderware Historian Client 2014 R2 SP1 and prior. An improperly restricted XML parser (with improper restriction of XML external entity ref...Show more |
1Redhat 1Jboss Enterprise Application Platform May 13, 2026 May 18, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server wh...Show more |
1Ibm 2Rational Quality Manager Rational Team ConcertMay 13, 2026 May 10, 2017 N/A· v4 8.1 HIGH· v3 7.5 HIGH· v2 IBM Team Concert (RTC) is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive...Show more |
1Ibm 1Websphere Cast Iron Solution May 13, 2026 May 5, 2017 N/A· v4 8.6 HIGH· v3 9.0 HIGH· v2 IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability...Show more |
IBM UrbanCode Deploy (UCD) 6.0, 6.1, and 6.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to ex...Show more |
1Modified Shop 1Modified Ecommerce Shopsoftware May 13, 2026 Apr 25, 2017 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 www.modified-shop.org modified eCommerce Shopsoftware 2.0.2.2 rev 10690 has XXE in api/it-recht-kanzlei/api-it-recht-kanzlei.php. |
1Oracle 1Peoplesoft Enterprise Peopletools May 13, 2026 Apr 24, 2017 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions that are affected are 8.54 and 8.55. Easily "exploitable" vulnerabilit...Show more |