CWE-611
1,268 CVEs • Abstraction: Base
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVEs (1,268)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
WatchGuard Fireware v11.12.1 and earlier mishandles requests referring to an XML External Entity (XXE), in the XML-RPC agent. This causes the Firebox wgagent process to crash. This process crash ends all authenticated se...Show more |
In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user conte...Show more |
1Apache 1Formatting Objects Processor May 13, 2026 Apr 18, 2017 N/A· v4 7.3 HIGH· v3 7.9 HIGH· v2 In Apache FOP before 2.2, files lying on the filesystem of the server which uses FOP can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context i...Show more |
1Fasterxml 1Jackson Dataformat Xml May 13, 2026 Apr 14, 2017 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DT...Show more |
XML External Entity via ".AOP" files used by Moxa MX-AOPC Server 1.5 result in remote file disclosure. |
1Dell 1Integrated Remote Access Controller Firmware May 13, 2026 Apr 10, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has XXE. |
Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier documents. |
1Ibm 7Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 moreMay 13, 2026 Mar 31, 2017 N/A· v4 8.1 HIGH· v3 7.5 HIGH· v2 IBM Jazz Foundation is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive inf...Show more |
1Ibm 1Curam Social Program Management May 13, 2026 Mar 31, 2017 N/A· v4 9.1 CRITICAL· v3 8.5 HIGH· v2 IBM Curam Social Program Management 6.0 and 7.0 are vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability t...Show more |
1Synacor 1Zimbra Collaboration Suite May 13, 2026 Mar 29, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zimbra Collaboration Suite (ZCS) before 8.7.4 allows remote attackers to conduct XML External Entity (XXE) attacks. |
2Debian Pysaml2 Project2Debian Linux Pysaml2May 13, 2026 Mar 24, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response. |
1Usb Pratirodh Project 1Usb Pratirodh May 13, 2026 Mar 23, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 USB Pratirodh allows remote attackers to conduct XML External Entity (XXE) attacks via XML data in usb.xml. |
NetIQ Access Manager 4.1 before 4.1.2 HF 1 and 4.2 before 4.2.2 was parsing incoming SAML requests with external entity resolution enabled, which could lead to local file disclosure via an XML External Entity (XXE) attac...Show more |
External Entity Processing (XXE) vulnerability in the "risk score" application of NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to disclose the content of local files to logged-in use...Show more |
XML entity injection in Junos Space before 15.2R2 allows attackers to cause a denial of service. |
1Cisco 1Webex Meetings Server May 13, 2026 Mar 17, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An XML External Entity vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to have read access to part of the information stored in the affected system. More Information: CSCvc39165...Show more |
1Ibm 1Qradar Security Information And Event Manager May 13, 2026 Mar 7, 2017 N/A· v4 8.1 HIGH· v3 7.5 HIGH· v2 IBM QRadar 7.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive informat...Show more |
PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response. |
XML External Entity (XXE) vulnerability in Grails PDF Plugin 0.6 allows remote attackers to read arbitrary files via a crafted XML document. |
1Ibm 1Rational Rhapsody Design Manager May 13, 2026 Feb 23, 2017 N/A· v4 8.1 HIGH· v3 7.5 HIGH· v2 IBM Rhapsody DM 4.0, 5.0 and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly...Show more |