CWE-611
1,268 CVEs • Abstraction: Base
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVEs (1,268)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM AppScan Source 8.7 through 9.0.3.3 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunct...Show more |
1Ibm 7Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 moreMay 6, 2026 Nov 24, 2016 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 The XML parser in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 bef...Show more |
1Sap 1Netweaver Application Server Java Apr 21, 2026 Nov 23, 2016 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909. |
2Canonical Xmlsoft2Libxml2 Ubuntu LinuxMay 6, 2026 Nov 16, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier...Show more |
XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows context-dependent attackers to read arbitrary files or cause a denial...Show more |
1Ibm 1Security Privileged Identity Manager Virtual Appliance May 6, 2026 Sep 26, 2016 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document cont...Show more |
Cisco Prime Home 5.2.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue,...Show more |
The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via a crafted OOXML spreadsheet...Show more |
The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to...Show more |
4Canonical OpensusePhp+1 more6Leap Linux Enterprise Module For Web ScriptingLinux Enterprise Software Development Kit+3 moreMay 6, 2026 May 22, 2016 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML...Show more |
1Sap 1Netweaver Application Server Java May 6, 2026 Apr 7, 2016 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to cause a denial of service, conduct SMB Relay attacks, or access arbitrary files via...Show more |
Unspecified vulnerability in HP WebInspect 7.x through 10.4 before 10.4 update 1 allows remote authenticated users to bypass intended access restrictions via unknown vectors. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraOpensuse+2 moreMay 6, 2026 May 12, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) loa...Show more |
3Castor Project OpensuseOpensuse Project3Castor OpensuseOpensuseMay 6, 2026 Jun 11, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document. |
2Pivotal Software Vmware2Spring Framework Spring FrameworkApr 29, 2026 Jan 26, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a den...Show more |
3Apple Libexpat ProjectPython7Ipados Iphone OsLibexpat+4 moreApr 29, 2026 Jan 21, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource cons...Show more |
3Apple PhpRedhat3Enterprise Linux Mac Os XPhpApr 29, 2026 Sep 16, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, rel...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraModsecurity+1 moreApr 29, 2026 Apr 25, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjun...Show more |
3Debian FedoraprojectZend3Debian Linux FedoraZend FrameworkApr 29, 2026 Feb 13, 2013 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external...Show more |
4Canonical FedoraprojectInkscape+1 more4Fedora InkscapeOpensuse+1 moreApr 29, 2026 Jan 18, 2013 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack. |