← Back
CWE-611

1,302 CVEs • Abstraction: Base

Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

JSON object

Loading...

CVEs (1,302)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Ignite
May 13, 2026
Apr 7, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier documents.
1Ibm
7Rational Collaborative Lifecycle Management
Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 more
May 13, 2026
Mar 31, 2017
N/A· v4
8.1 HIGH· v3
7.5 HIGH· v2
IBM Jazz Foundation is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive inf...Show more
IBM Jazz Foundation is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 2000784.Show less
1Ibm
1Curam Social Program Management
May 13, 2026
Mar 31, 2017
N/A· v4
9.1 CRITICAL· v3
8.5 HIGH· v2
IBM Curam Social Program Management 6.0 and 7.0 are vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability t...Show more
IBM Curam Social Program Management 6.0 and 7.0 are vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 2000833.Show less
1Synacor
1Zimbra Collaboration Suite
May 13, 2026
Mar 29, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zimbra Collaboration Suite (ZCS) before 8.7.4 allows remote attackers to conduct XML External Entity (XXE) attacks.
2Debian
Pysaml2 Project
2Debian Linux
Pysaml2
May 13, 2026
Mar 24, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.
1Usb Pratirodh Project
1Usb Pratirodh
May 13, 2026
Mar 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
USB Pratirodh allows remote attackers to conduct XML External Entity (XXE) attacks via XML data in usb.xml.
1Netiq
1Access Manager
May 13, 2026
Mar 23, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
NetIQ Access Manager 4.1 before 4.1.2 HF 1 and 4.2 before 4.2.2 was parsing incoming SAML requests with external entity resolution enabled, which could lead to local file disclosure via an XML External Entity (XXE) attac...Show more
NetIQ Access Manager 4.1 before 4.1.2 HF 1 and 4.2 before 4.2.2 was parsing incoming SAML requests with external entity resolution enabled, which could lead to local file disclosure via an XML External Entity (XXE) attack.Show less
1Netiq
1Access Manager
May 13, 2026
Mar 23, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
External Entity Processing (XXE) vulnerability in the "risk score" application of NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to disclose the content of local files to logged-in use...Show more
External Entity Processing (XXE) vulnerability in the "risk score" application of NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to disclose the content of local files to logged-in users.Show less
1Juniper
1Junos Space
May 13, 2026
Mar 20, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
XML entity injection in Junos Space before 15.2R2 allows attackers to cause a denial of service.
1Cisco
1Webex Meetings Server
May 13, 2026
Mar 17, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An XML External Entity vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to have read access to part of the information stored in the affected system. More Information: CSCvc39165...Show more
An XML External Entity vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to have read access to part of the information stored in the affected system. More Information: CSCvc39165. Known Affected Releases: 2.6. Known Fixed Releases: 2.7.1.2054.Show less
1Ibm
1Qradar Security Information And Event Manager
May 13, 2026
Mar 7, 2017
N/A· v4
8.1 HIGH· v3
7.5 HIGH· v2
IBM QRadar 7.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive informat...Show more
IBM QRadar 7.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 1999537.Show less
1Pysaml2 Project
1Pysaml2
May 13, 2026
Mar 3, 2017
N/A· v4
9.0 CRITICAL· v3
6.8 MEDIUM· v2
PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.
1Grails
1Pdf Plugin
May 13, 2026
Feb 27, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
XML External Entity (XXE) vulnerability in Grails PDF Plugin 0.6 allows remote attackers to read arbitrary files via a crafted XML document.
1Ibm
1Rational Rhapsody Design Manager
May 13, 2026
Feb 23, 2017
N/A· v4
8.1 HIGH· v3
7.5 HIGH· v2
IBM Rhapsody DM 4.0, 5.0 and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly...Show more
IBM Rhapsody DM 4.0, 5.0 and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 1997798.Show less
1Cisco
1Secure Access Control System
May 13, 2026
Feb 22, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An XML External Entity vulnerability in the web-based user interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to have read access to part of the information stored i...Show more
An XML External Entity vulnerability in the web-based user interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to have read access to part of the information stored in the affected system. More Information: CSCvc04845. Known Affected Releases: 5.8(2.5).Show less
1Eparaksts
1Eparakstitajs 3
May 13, 2026
Feb 17, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
XML external entity (XXE) vulnerability in eParakstitajs 3 before 1.3.9 and eParaksts Java lib before 2.5.13 allows remote attackers to read arbitrary files or possibly have unspecified other impact via a crafted edoc fi...Show more
XML external entity (XXE) vulnerability in eParakstitajs 3 before 1.3.9 and eParaksts Java lib before 2.5.13 allows remote attackers to read arbitrary files or possibly have unspecified other impact via a crafted edoc file.Show less
1Wso2
1Identity Server
May 13, 2026
Feb 17, 2017
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH-4.4.0-0231 allows remote authenticated users with access to XACML features to read arbitrary files,...Show more
XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH-4.4.0-0231 allows remote authenticated users with access to XACML features to read arbitrary files, cause a denial of service, conduct server-side request forgery (SSRF) attacks, or have unspecified other impact via a crafted XACML request to entitlement/eval-policy-submit.jsp. NOTE: this issue can be combined with CVE-2016-4311 to exploit the vulnerability without credentials.Show less
1Python
1Openpyxl
May 13, 2026
Feb 15, 2017
N/A· v4
8.2 HIGH· v3
5.8 MEDIUM· v2
Openpyxl 2.4.1 resolves external entities by default, which allows remote attackers to conduct XXE attacks via a crafted .xlsx document.
1Ibm
2Integration Bus
Websphere Message Broker
May 13, 2026
Feb 15, 2017
N/A· v4
9.1 CRITICAL· v3
8.5 HIGH· v2
IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could expl...Show more
IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 1997918.Show less
1Emerson
1Liebert Sitescan Web
May 13, 2026
Feb 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An XML External Entity (XXE) issue was discovered in Emerson Liebert SiteScan Web Version 6.5, and prior. An attacker may enter malicious input to Liebert SiteScan through a weakly configured XML parser causing the appli...Show more
An XML External Entity (XXE) issue was discovered in Emerson Liebert SiteScan Web Version 6.5, and prior. An attacker may enter malicious input to Liebert SiteScan through a weakly configured XML parser causing the application to execute arbitrary code or disclose file contents from a server or connected network.Show less