← Back
CWE-611

1,249 CVEs • Abstraction: Base

Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

JSON object

Loading...

CVEs (1,249)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Alkacon
1Opencms
Nov 21, 2024
Oct 8, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by uploading a crafted SVG do...Show more
An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by uploading a crafted SVG document.Show less
1Zohocorp
1Manageengine Admanager Plus
Nov 21, 2024
Oct 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.
1Apache
1Openoffice
Nov 21, 2024
Oct 7, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion Laughs" entity expansion denial of service attack and exploit via crafted XML files. ODF files consis...Show more
Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion Laughs" entity expansion denial of service attack and exploit via crafted XML files. ODF files consist of a set of XML files. All versions of Apache OpenOffice up to 4.1.10 are subject to this issue. expat in version 4.1.11 is patched.Show less
1Pingidentity
1Pingfederate
Nov 21, 2024
Oct 7, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.
1Cisco
1Identity Services Engine
Nov 21, 2024
Oct 6, 2021
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information or conduct a server-side request forgery (SSRF)...Show more
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information or conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by uploading a crafted XML file that contains references to external entities. A successful exploit could allow the attacker to retrieve files from the local system, resulting in the disclosure of sensitive information, or cause the web application to perform arbitrary HTTP requests on behalf of the attacker.Show less
1Netscout
1Ngeniusone
Nov 21, 2024
Sep 30, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
NEI in NETSCOUT nGeniusONE 6.3.0 build 1196 allows XML External Entity (XXE) attacks.
1Nokogiri
1Nokogiri
Nov 21, 2024
Sep 27, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri v1.12.4 and earlier, on JRuby only, the SAX parser resolves external entities by default. Users of Nokog...Show more
Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri v1.12.4 and earlier, on JRuby only, the SAX parser resolves external entities by default. Users of Nokogiri on JRuby who parse untrusted documents using any of these classes are affected: Nokogiri::XML::SAX::Parse, Nokogiri::HTML4::SAX::Parser or its alias Nokogiri::HTML::SAX::Parser, Nokogiri::XML::SAX::PushParser, and Nokogiri::HTML4::SAX::PushParser or its alias Nokogiri::HTML::SAX::PushParser. JRuby users should upgrade to Nokogiri v1.12.5 or later to receive a patch for this issue. There are no workarounds available for v1.12.4 or earlier. CRuby users are not affected.Show less
1Ibm
2Jazz For Service Management
Tivoli Netcool/omnibus Gui
Nov 21, 2024
Sep 21, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to e...Show more
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 204775.Show less
1Apache
1Jena
Nov 21, 2024
Sep 16, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including exposing the contents of local files to a remote server.
1Axiossystems
1Assyst
Nov 21, 2024
Sep 15, 2021
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
Assyst 10 SP7.5 has authenticated XXE leading to SSRF via XML unmarshalling. The application allows users to send JSON or XML data to the server. It was possible to inject malicious XML data through several access points...Show more
Assyst 10 SP7.5 has authenticated XXE leading to SSRF via XML unmarshalling. The application allows users to send JSON or XML data to the server. It was possible to inject malicious XML data through several access points.Show less
1Siemens
1Teamcenter Visualization
Nov 21, 2024
Sep 14, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). Th...Show more
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application server filesystem.Show less
1Apache
1Any23
Nov 21, 2024
Sep 11, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. XML external entity injection (also known as XXE) is a web security vuln...Show more
An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's processing of XML data. It often allows an attacker to view files on the application server filesystem, and to interact with any back-end or external systems that the application itself can access.Show less
1Paloaltonetworks
1Pan Os
Nov 21, 2024
Sep 8, 2021
N/A· v4
6.5 MEDIUM· v3
7.5 HIGH· v2
An improper restriction of XML external entity (XXE) reference vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system and send...Show more
An improper restriction of XML external entity (XXE) reference vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system and send a specifically crafted request to the firewall that causes the service to crash. Repeated attempts to send this request result in denial of service to all PAN-OS services by restarting the device and putting it into maintenance mode. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14; PAN-OS 9.1 versions earlier than PAN-OS 9.1.10; PAN-OS 10.0 versions earlier than PAN-OS 10.0.6. This issue does not affect Prisma Access.Show less
1Eclipse
1Theia
Nov 21, 2024
Sep 2, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. This extension uses lsp4xml (recently renamed to LemMinX) in order to pr...Show more
In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. This extension uses lsp4xml (recently renamed to LemMinX) in order to provide language support for XML. This is installed by default.Show less
1Jenkins
1Nested View
Nov 21, 2024
Aug 31, 2021
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
Jenkins Nested View Plugin 1.20 and earlier does not configure its XML transformer to prevent XML external entity (XXE) attacks.
2Debian
Osgeo
3Debian Linux
OwslibPywps
Nov 21, 2024
Aug 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server filesystem by assigning a path to the entity. OWSLib 0.24.1 may also be affected.
1Quokka Project
1Quokka
Nov 21, 2024
Aug 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/core/content/views.py'.
1Quokka Project
1Quokka
Nov 21, 2024
Aug 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/utils/atom.py'.
1On24
1Screenshare
Nov 21, 2024
Aug 13, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The ON24 ScreenShare (aka DesktopScreenShare.app) plugin before 2.0 for macOS allows remote file access via its built-in HTTP server. This allows unauthenticated remote users to retrieve files accessible to the logged-on...Show more
The ON24 ScreenShare (aka DesktopScreenShare.app) plugin before 2.0 for macOS allows remote file access via its built-in HTTP server. This allows unauthenticated remote users to retrieve files accessible to the logged-on macOS user. When a remote user sends a crafted HTTP request to the server, it triggers a code path that will download a configuration file from a specified remote machine over HTTP. There is an XXE flaw in processing of this configuration file that allows reading local (to macOS) files and uploading them to remote machines.Show less
1Hcltechsw
1Hcl Commerce
Nov 21, 2024
Aug 13, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
" Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"