CWE-611
1,302 CVEs • Abstraction: Base
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVEs (1,302)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
XML External Entity (XXE) vulnerability in Milton Webdav before 2.7.0.3. |
An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.1R1 may allow an authenticated user to read arbitrary files on the device. |
XXE vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Replication Manager before 8.5.2-00 allows authenticated remote users to read arbitrary files. |
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcellerator/exec/soap/vP.001sap0003.in_WCSX/com.sap.b1i.vplatform.runtime/IN...Show more |
2Pivotal Software Vmware2Spring Framework Spring FrameworkMay 13, 2026 May 25, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration...Show more |
1Sap 1Netweaver Application Server Java May 13, 2026 May 23, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via a crafted XML document in a request to irj/servlet/prt/portal/prtr...Show more |
IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memo...Show more |
1Schneider Electric 1Wonderware Historian Client May 13, 2026 May 19, 2017 N/A· v4 6.6 MEDIUM· v3 3.3 LOW· v2 An Improper XML Parser Configuration issue was discovered in Schneider Electric Wonderware Historian Client 2014 R2 SP1 and prior. An improperly restricted XML parser (with improper restriction of XML external entity ref...Show more |
1Redhat 1Jboss Enterprise Application Platform May 13, 2026 May 18, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server wh...Show more |
1Ibm 2Rational Quality Manager Rational Team ConcertMay 13, 2026 May 10, 2017 N/A· v4 8.1 HIGH· v3 7.5 HIGH· v2 IBM Team Concert (RTC) is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive...Show more |
1Ibm 1Websphere Cast Iron Solution May 13, 2026 May 5, 2017 N/A· v4 8.6 HIGH· v3 9.0 HIGH· v2 IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability...Show more |
IBM UrbanCode Deploy (UCD) 6.0, 6.1, and 6.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to ex...Show more |
1Modified Shop 1Modified Ecommerce Shopsoftware May 13, 2026 Apr 25, 2017 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 www.modified-shop.org modified eCommerce Shopsoftware 2.0.2.2 rev 10690 has XXE in api/it-recht-kanzlei/api-it-recht-kanzlei.php. |
1Oracle 1Peoplesoft Enterprise Peopletools May 13, 2026 Apr 24, 2017 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions that are affected are 8.54 and 8.55. Easily "exploitable" vulnerabilit...Show more |
WatchGuard Fireware v11.12.1 and earlier mishandles requests referring to an XML External Entity (XXE), in the XML-RPC agent. This causes the Firebox wgagent process to crash. This process crash ends all authenticated se...Show more |
In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user conte...Show more |
1Apache 1Formatting Objects Processor May 13, 2026 Apr 18, 2017 N/A· v4 7.3 HIGH· v3 7.9 HIGH· v2 In Apache FOP before 2.2, files lying on the filesystem of the server which uses FOP can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context i...Show more |
1Fasterxml 1Jackson Dataformat Xml May 13, 2026 Apr 14, 2017 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DT...Show more |
XML External Entity via ".AOP" files used by Moxa MX-AOPC Server 1.5 result in remote file disclosure. |
1Dell 1Integrated Remote Access Controller Firmware May 13, 2026 Apr 10, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has XXE. |