← Back
CWE-611

1,249 CVEs • Abstraction: Base

Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

JSON object

Loading...

CVEs (1,249)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Connectwise
1Automate
Nov 21, 2024
Jun 21, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.
1Powerarchiver
1Powerarchiver
Nov 21, 2024
Jun 21, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The XML parser used in ConeXware PowerArchiver before 20.10.02 allows processing of external entities, which might lead to exfiltration of local files over the network (via an XXE attack).
5Apache
DebianFedoraproject+2 more
6Communications Messaging Server
Debian LinuxFedora+3 more
Nov 21, 2024
Jun 16, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.
1Ibm
1Financial Transaction Manager
Nov 21, 2024
Jun 11, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
IBM Financial Transaction Manager 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consu...Show more
IBM Financial Transaction Manager 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192956.Show less
1Sap
1Netweaver Application Server For Java
Nov 21, 2024
Jun 9, 2021
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
SAP NetWeaver AS for JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker authenticated as an administrator to connect over a network and submit a specially crafted XML file in the application because of mis...Show more
SAP NetWeaver AS for JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker authenticated as an administrator to connect over a network and submit a specially crafted XML file in the application because of missing XML Validation, this vulnerability enables attacker to fully compromise confidentiality by allowing them to read any file on the filesystem or fully compromise availability by causing the system to crash. The attack cannot be used to change any data so that there is no compromise as to integrity.Show less
1Silverstripe
1Silverstripe
Nov 21, 2024
Jun 8, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser. A developer utility meant for parsing HTML within unit tests can be vulnerable to XML External Entity (XXE) attacks. When this developer utilit...Show more
SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser. A developer utility meant for parsing HTML within unit tests can be vulnerable to XML External Entity (XXE) attacks. When this developer utility is misused for purposes involving external or user submitted data in custom project code, it can lead to vulnerabilities such as XSS on HTML output rendered through this custom code. This is now mitigated by disabling external entities during parsing. (The correct CVE ID year is 2020 [CVE-2020-25817, not CVE-2021-25817]).Show less
2Ibm
Netapp
2Cognos Analytics
Oncommand Insight
Nov 21, 2024
Jun 1, 2021
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume me...Show more
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 176607.Show less
2Ibm
Netapp
2Cognos Analytics
Oncommand Insight
Nov 21, 2024
Jun 1, 2021
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume me...Show more
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 172533.Show less
3Datakit
LuxionSiemens
4Crosscadware
KeyshotSolid Edge Se2020 Firmware+1 more
Nov 21, 2024
May 27, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
When opening a specially crafted 3DXML file, the application containing Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior could di...Show more
When opening a specially crafted 3DXML file, the application containing Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior could disclose arbitrary files to remote attackers. This is because of the passing of specially crafted content to the underlying XML parser without taking proper restrictions such as prohibiting an external DTD.Show less
1Ibm
1Websphere Application Server
Nov 21, 2024
May 26, 2021
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose...Show more
IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 197793.Show less
1Chamilo
1Chamilo
Nov 21, 2024
May 13, 2021
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities.
1Elastic
1Elastic App Search
Nov 21, 2024
May 13, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an attacker whose website is being crawled by...Show more
Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an attacker whose website is being crawled by App Search could craft a malicious sitemap.xml to traverse the filesystem of the host running the instance and obtain sensitive files.Show less
1Jetbrains
1Intellij Idea
Nov 21, 2024
May 11, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.
1Paxtechnology
1Paxstore
Nov 21, 2024
May 7, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection. An authenticated attacker can compromise the private keys of a JWT token and reuse them to manipulate the access...Show more
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection. An authenticated attacker can compromise the private keys of a JWT token and reuse them to manipulate the access tokens to access the platform as any desired user (clients and administrators).Show less
1Cisco
1Broadworks Messaging Server
Nov 21, 2024
May 6, 2021
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco BroadWorks Messaging Server Software could allow an authenticated, remote attacker to access sensitive information or cause a partial denial of service (DoS)...Show more
A vulnerability in the web-based management interface of Cisco BroadWorks Messaging Server Software could allow an authenticated, remote attacker to access sensitive information or cause a partial denial of service (DoS) condition on an affected system. This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by uploading a crafted XML file that contains references to external entities. A successful exploit could allow the attacker to retrieve files from the local system, resulting in the disclosure of sensitive information, or cause the application to consume available resources, resulting in a partial DoS condition on an affected system. There are workarounds that address this vulnerability.Show less
1Ibm
1Qradar Security Information And Event Manager
Nov 21, 2024
May 5, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
IBM QRadar SIEM 7.3 and 7.4 may vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory re...Show more
IBM QRadar SIEM 7.3 and 7.4 may vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 193245.Show less
1Cisco
1Firepower Device Manager
Nov 21, 2024
Apr 29, 2021
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected device. Thi...Show more
A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected device. This vulnerability is due to the improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by sending malicious requests that contain references in XML entities to an affected system. A successful exploit could allow the attacker to retrieve files from the local system, resulting in the disclosure of sensitive information or causing a partial denial of service (DoS) condition on the affected device.Show less
1Arubanetworks
1Clearpass
Nov 21, 2024
Apr 29, 2021
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
A remote XML external entity (XXE) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address...Show more
A remote XML external entity (XXE) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address this security vulnerability.Show less
1Arubanetworks
1Airwave
Nov 21, 2024
Apr 29, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerabi...Show more
A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.Show less
1Avaya
1Equinox Conferencing
Nov 21, 2024
Apr 28, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
An XML External Entities (XXE) vulnerability in Media Server component of Avaya Equinox Conferencing could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system o...Show more
An XML External Entities (XXE) vulnerability in Media Server component of Avaya Equinox Conferencing could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system or even potentially lead to a denial of service. The affected versions of Avaya Equinox Conferencing includes all 9.x versions before 9.1.11. Equinox Conferencing is now offered as Avaya Meetings Server.Show less