← Back
CWE-611

1,302 CVEs • Abstraction: Base

Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

JSON object

Loading...

CVEs (1,302)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Milton
1Webdav
May 13, 2026
Jun 7, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
XML External Entity (XXE) vulnerability in Milton Webdav before 2.7.0.3.
1Juniper
1Junos Space
May 13, 2026
May 30, 2017
N/A· v4
6.5 MEDIUM· v3
5.0 MEDIUM· v2
An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.1R1 may allow an authenticated user to read arbitrary files on the device.
1Hitachi
1Device Manager
May 13, 2026
May 29, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
XXE vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Replication Manager before 8.5.2-00 allows authenticated remote users to read arbitrary files.
1Sap
1Business One
May 13, 2026
May 26, 2017
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcellerator/exec/soap/vP.001sap0003.in_WCSX/com.sap.b1i.vplatform.runtime/IN...Show more
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcellerator/exec/soap/vP.001sap0003.in_WCSX/com.sap.b1i.vplatform.runtime/INB_WS_CALL_SYNC_XPT/INB_WS_CALL_SYNC_XPT.ipo/proc, aka SAP Security Note 2378065.Show less
2Pivotal Software
Vmware
2Spring Framework
Spring Framework
May 13, 2026
May 25, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration...Show more
When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.Show less
1Sap
1Netweaver Application Server Java
May 13, 2026
May 23, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via a crafted XML document in a request to irj/servlet/prt/portal/prtr...Show more
The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via a crafted XML document in a request to irj/servlet/prt/portal/prtroot/com.sap.visualcomposer.BIKit.default, aka SAP Security Note 2386873.Show less
1Ibm
1Sdk
May 13, 2026
May 22, 2017
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memo...Show more
IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 125150.Show less
1Schneider Electric
1Wonderware Historian Client
May 13, 2026
May 19, 2017
N/A· v4
6.6 MEDIUM· v3
3.3 LOW· v2
An Improper XML Parser Configuration issue was discovered in Schneider Electric Wonderware Historian Client 2014 R2 SP1 and prior. An improperly restricted XML parser (with improper restriction of XML external entity ref...Show more
An Improper XML Parser Configuration issue was discovered in Schneider Electric Wonderware Historian Client 2014 R2 SP1 and prior. An improperly restricted XML parser (with improper restriction of XML external entity reference, or XXE) may allow an attacker to enter malicious input through the application which could cause a denial of service or disclose file contents from a server or connected network.Show less
1Redhat
1Jboss Enterprise Application Platform
May 13, 2026
May 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server wh...Show more
It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.Show less
1Ibm
2Rational Quality Manager
Rational Team Concert
May 13, 2026
May 10, 2017
N/A· v4
8.1 HIGH· v3
7.5 HIGH· v2
IBM Team Concert (RTC) is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive...Show more
IBM Team Concert (RTC) is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM X-Force ID: 120665.Show less
1Ibm
1Websphere Cast Iron Solution
May 13, 2026
May 5, 2017
N/A· v4
8.6 HIGH· v3
9.0 HIGH· v2
IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability...Show more
IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM X-Force ID: 119515.Show less
1Ibm
1Urbancode Deploy
May 13, 2026
Apr 25, 2017
N/A· v4
8.1 HIGH· v3
7.5 HIGH· v2
IBM UrbanCode Deploy (UCD) 6.0, 6.1, and 6.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to ex...Show more
IBM UrbanCode Deploy (UCD) 6.0, 6.1, and 6.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM X-Force ID: 122202.Show less
1Modified Shop
1Modified Ecommerce Shopsoftware
May 13, 2026
Apr 25, 2017
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
www.modified-shop.org modified eCommerce Shopsoftware 2.0.2.2 rev 10690 has XXE in api/it-recht-kanzlei/api-it-recht-kanzlei.php.
1Oracle
1Peoplesoft Enterprise Peopletools
May 13, 2026
Apr 24, 2017
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions that are affected are 8.54 and 8.55. Easily "exploitable" vulnerabilit...Show more
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions that are affected are 8.54 and 8.55. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.0 Base Score 6.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).Show less
1Watchguard
1Fireware
May 13, 2026
Apr 22, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
WatchGuard Fireware v11.12.1 and earlier mishandles requests referring to an XML External Entity (XXE), in the XML-RPC agent. This causes the Firebox wgagent process to crash. This process crash ends all authenticated se...Show more
WatchGuard Fireware v11.12.1 and earlier mishandles requests referring to an XML External Entity (XXE), in the XML-RPC agent. This causes the Firebox wgagent process to crash. This process crash ends all authenticated sessions to the Firebox, including management connections, and prevents new authenticated sessions until the process has recovered. The Firebox may also experience an overall degradation in performance while the wgagent process recovers. An attacker could continuously send XML-RPC requests that contain references to external entities to perform a limited Denial of Service (DoS) attack against an affected Firebox.Show less
1Apache
1Batik
May 13, 2026
Apr 18, 2017
N/A· v4
7.3 HIGH· v3
7.9 HIGH· v2
In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user conte...Show more
In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is running. If the user is root a full compromise of the server - including confidential or sensitive files - would be possible. XXE can also be used to attack the availability of the server via denial of service as the references within a xml document can trivially trigger an amplification attack.Show less
1Apache
1Formatting Objects Processor
May 13, 2026
Apr 18, 2017
N/A· v4
7.3 HIGH· v3
7.9 HIGH· v2
In Apache FOP before 2.2, files lying on the filesystem of the server which uses FOP can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context i...Show more
In Apache FOP before 2.2, files lying on the filesystem of the server which uses FOP can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is running. If the user is root a full compromise of the server - including confidential or sensitive files - would be possible. XXE can also be used to attack the availability of the server via denial of service as the references within a xml document can trivially trigger an amplification attack.Show less
1Fasterxml
1Jackson Dataformat Xml
May 13, 2026
Apr 14, 2017
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DT...Show more
XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DTD.Show less
1Moxa
1Mx Aopc Server
May 13, 2026
Apr 14, 2017
N/A· v4
5.0 MEDIUM· v3
1.9 LOW· v2
XML External Entity via ".AOP" files used by Moxa MX-AOPC Server 1.5 result in remote file disclosure.
1Dell
1Integrated Remote Access Controller Firmware
May 13, 2026
Apr 10, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has XXE.