CWE-611
1,244 CVEs • Abstraction: Base
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVEs (1,244)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 1Websphere Application Server Nov 21, 2024 Feb 10, 2021 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive info...Show more |
openHAB is a vendor and technology agnostic open source automation software for your home. In openHAB before versions 2.5.12 and 3.0.1 the XML external entity (XXE) attack allows attackers in the same network as the open...Show more |
1Ibm 1Websphere Application Server Nov 21, 2024 Jan 26, 2021 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive info...Show more |
2Apache Netapp2Nutch Snap Creator FrameworkNov 21, 2024 Jan 25, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web security vulnerability...Show more |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5. Authentication is not required to exploit this vulnerability. The specific flaw exists withi...Show more |
1Microfocus 1Application Lifecycle Management Nov 21, 2024 Jan 19, 2021 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 XML External Entity Injection vulnerability in Micro Focus Application Lifecycle Management (Previously known as Quality Center) product. The vulnerability affects versions 12.x, 12.60 Patch 5 and earlier, 15.0.1 Patch 2...Show more |
OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input. This allows an attacker to inject arbitrary HTML or XML into embedding documents. |
1Siemens 2Jt2go Teamcenter VisualizationNov 21, 2024 Jan 12, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). When opening a specially crafted xml file, the application could disclose arbitrary files to remot...Show more |
The TIBCO EBX Add-on for Oracle Hyperion EPM, TIBCO EBX Data Exchange Add-on, and TIBCO EBX Insight Add-on components of TIBCO Software Inc.'s TIBCO EBX Add-ons contain a vulnerability that theoretically allows a low pri...Show more |
1Sap 1Enterprise Performance Management Nov 21, 2024 Jan 12, 2021 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 SAP EPM Add-in for Microsoft Office, version - 1010 and SAP EPM Add-in for SAP Analysis Office, version - 2.8, allows an authenticated attacker with user privileges to parse malicious XML files which could result in XXE-...Show more |
1Ibm 1Security Verify Privilege Manager Nov 21, 2024 Jan 8, 2021 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 IBM Security Verify Privilege Manager 10.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A local attacker could exploit this vulnerability to expose sensitive information or con...Show more |
Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager role). |
Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role. |
2Debian Nokogiri2Debian Linux NokogiriNov 21, 2024 Dec 30, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are...Show more |
1Kronos 1Web Time And Attendance Nov 21, 2024 Dec 21, 2020 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 An XXE attack can occur in Kronos WebTA 5.0.4 when SAML is used. |
In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store extension, which is vulnerable to XXE attacks. This has been fixed in Zimbra...Show more |
1Sonatype 1Nexus Repository Manager Nov 21, 2024 Dec 17, 2020 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of NXRM via an XXE vulnerability. Fixed in version 3.29.0. |
An issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The ReqIF XML data, used by the codebeamer ALM application to import projects, is parsed by insecurely configured software components, which can be...Show more |
6Apache FasterxmlFedoraproject+3 more39Agile Plm Agile Product Lifecycle Management Integration PackBanking Apis+36 moreNov 21, 2024 Dec 3, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is...Show more |
Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |