CWE-611
1,302 CVEs • Abstraction: Base
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVEs (1,302)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 2Bigfix Inventory License Metric ToolMay 13, 2026 Feb 1, 2017 N/A· v4 8.1 HIGH· v3 7.5 HIGH· v2 IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive...Show more |
1Ibm 3Infosphere Datastage Infosphere Information ServerInfosphere Information Server On CloudMay 13, 2026 Feb 1, 2017 N/A· v4 8.1 HIGH· v3 7.5 HIGH· v2 IBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly...Show more |
1Ibm 3Security Access Manager 9.0 Firmware Security Access Manager For Mobile 8.0 FirmwareSecurity Access Manager For Web 8.0 FirmwareMay 13, 2026 Feb 1, 2017 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose high...Show more |
1Ibm 3Security Access Manager 9.0 Firmware Security Access Manager For Mobile 8.0 FirmwareSecurity Access Manager For Web 8.0 FirmwareMay 13, 2026 Feb 1, 2017 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 IBM Single Sign On for Bluemix could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML data by the XML parser. A remote attacker could exploit this v...Show more |
1Paessler 1Prtg Network Monitor May 13, 2026 Jan 23, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 XML external entity vulnerability in PRTG Network Monitor before 16.2.23.3077/3078 allows remote authenticated users to read arbitrary files by creating a new HTTP XML/REST Value sensor that accesses a crafted XML file. |
XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to read arbitrary files via the SAMLRequest parameter. |
1Vmware 1Vrealize Automation May 6, 2026 Dec 29, 2016 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML docum...Show more |
VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distributed Switch setup, or (3) Content Library XML document containing an ext...Show more |
VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity...Show more |
1Image Info Project 1Image Info For Perl May 6, 2026 Dec 22, 2016 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of servic...Show more |
perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's setting. |
1Python Openxml Project 1Python Docx May 6, 2026 Dec 21, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 python-docx before 0.8.6 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted document. |
1Open Xchange 1Open Xchange Appsuite May 6, 2026 Dec 15, 2016 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev8. References to external Open XML document type definitions (.dtd resources) can be placed within .docx and .xslx files. Those resources were requeste...Show more |
IBM FileNet Workplace 4.0.2 before 4.0.2.14 LA012 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration...Show more |
IBM AppScan Source 8.7 through 9.0.3.3 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunct...Show more |
1Ibm 7Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 moreMay 6, 2026 Nov 24, 2016 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 The XML parser in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 bef...Show more |
1Sap 1Netweaver Application Server Java Apr 21, 2026 Nov 23, 2016 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909. |
2Canonical Xmlsoft2Libxml2 Ubuntu LinuxMay 6, 2026 Nov 16, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier...Show more |
XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows context-dependent attackers to read arbitrary files or cause a denial...Show more |
1Ibm 1Security Privileged Identity Manager Virtual Appliance May 6, 2026 Sep 26, 2016 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document cont...Show more |