CWE-611
1,302 CVEs • Abstraction: Base
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVEs (1,302)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
XML External Entity (XXE) vulnerability in Apache Wink 1.1.1 and earlier allows remote attackers to read arbitrary files or cause a denial of service via a crafted XML document. |
XML external entity (XXE) processing vulnerability in Trend Micro Control Manager 6.0, if exploited, could lead to information disclosure. Formerly ZDI-CAN-4706. |
1Ibm 2Sterling B2b Integrator Sterling File GatewayMay 13, 2026 Aug 2, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling File Gateway 2.1 and 2.2 allows remote attackers to read arbitrary files via a crafted XML data. |
1Ibm 1Infosphere Information Server May 13, 2026 Aug 2, 2017 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive informa...Show more |
3Debian Libexpat ProjectPython3Debian Linux LibexpatPythonMay 13, 2026 Jul 25, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD. |
1Sap 1Netweaver Application Server Java May 13, 2026 Jul 25, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD...Show more |
IBM Tivoli Endpoint Manager is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory res...Show more |
In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string, which allows for XXE attacks in all scripts which use this method to...Show more |
Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0. |
xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information disclosure or denial of service |
LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents. |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 13, 2026 Jul 11, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Windows System Information Console in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an...Show more |
1Microsoft 6Windows 10 Windows 7Windows 8.1+3 moreMay 13, 2026 Jul 11, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Windows Performance Monitor in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an informa...Show more |
IBM Security Guardium 10.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memo...Show more |
1Xoev 1Osci Transport Library May 13, 2026 Jun 30, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An XML External Entity (XXE) issue exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET), exploitable by sending a crafted standard-conforming OSCI message from...Show more |
IBM API Connect 5.0.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory...Show more |
1Cisco 2Evolved Programmable Network Manager Prime InfrastructureMay 13, 2026 Jun 26, 2017 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker read and write access to information stored...Show more |
XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obtain sensitive information via unspecified vectors. |
1Ibm 1Rational Rhapsody Design Manager May 13, 2026 Jun 8, 2017 N/A· v4 8.1 HIGH· v3 7.5 HIGH· v2 IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly...Show more |
1Ibm 1Cognos Business Intelligence May 13, 2026 Jun 7, 2017 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 IBM Cognos Business Intelligence 10.1 and 10.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote authenticated attacker could exploit this vul...Show more |