← Back
CWE-611

1,303 CVEs • Abstraction: Base

Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

JSON object

Loading...

CVEs (1,303)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Ibm
Netapp
2Cognos Analytics
Oncommand Insight
Jun 17, 2026
Jun 1, 2021
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume me...Show more
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 176607.Show less
2Ibm
Netapp
2Cognos Analytics
Oncommand Insight
Jun 17, 2026
Jun 1, 2021
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume me...Show more
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 172533.Show less
3Datakit
LuxionSiemens
4Crosscadware
KeyshotSolid Edge Se2020 Firmware+1 more
Jun 17, 2026
May 27, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
When opening a specially crafted 3DXML file, the application containing Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior could di...Show more
When opening a specially crafted 3DXML file, the application containing Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior could disclose arbitrary files to remote attackers. This is because of the passing of specially crafted content to the underlying XML parser without taking proper restrictions such as prohibiting an external DTD.Show less
1Ibm
1Websphere Application Server
Jun 17, 2026
May 26, 2021
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose...Show more
IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 197793.Show less
1Chamilo
1Chamilo
Jun 17, 2026
May 13, 2021
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities.
1Elastic
1Elastic App Search
Jun 17, 2026
May 13, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an attacker whose website is being crawled by...Show more
Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an attacker whose website is being crawled by App Search could craft a malicious sitemap.xml to traverse the filesystem of the host running the instance and obtain sensitive files.Show less
1Jetbrains
1Intellij Idea
Jun 17, 2026
May 11, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.
1Paxtechnology
1Paxstore
Jun 17, 2026
May 7, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection. An authenticated attacker can compromise the private keys of a JWT token and reuse them to manipulate the access...Show more
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection. An authenticated attacker can compromise the private keys of a JWT token and reuse them to manipulate the access tokens to access the platform as any desired user (clients and administrators).Show less
1Cisco
1Broadworks Messaging Server
Jun 17, 2026
May 6, 2021
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco BroadWorks Messaging Server Software could allow an authenticated, remote attacker to access sensitive information or cause a partial denial of service (DoS)...Show more
A vulnerability in the web-based management interface of Cisco BroadWorks Messaging Server Software could allow an authenticated, remote attacker to access sensitive information or cause a partial denial of service (DoS) condition on an affected system. This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by uploading a crafted XML file that contains references to external entities. A successful exploit could allow the attacker to retrieve files from the local system, resulting in the disclosure of sensitive information, or cause the application to consume available resources, resulting in a partial DoS condition on an affected system. There are workarounds that address this vulnerability.Show less
1Ibm
1Qradar Security Information And Event Manager
Jun 17, 2026
May 5, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
IBM QRadar SIEM 7.3 and 7.4 may vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory re...Show more
IBM QRadar SIEM 7.3 and 7.4 may vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 193245.Show less
1Cisco
1Firepower Device Manager
Jun 17, 2026
Apr 29, 2021
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected device. Thi...Show more
A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected device. This vulnerability is due to the improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by sending malicious requests that contain references in XML entities to an affected system. A successful exploit could allow the attacker to retrieve files from the local system, resulting in the disclosure of sensitive information or causing a partial denial of service (DoS) condition on the affected device.Show less
1Arubanetworks
1Clearpass
Jun 17, 2026
Apr 29, 2021
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
A remote XML external entity (XXE) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address...Show more
A remote XML external entity (XXE) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address this security vulnerability.Show less
1Arubanetworks
1Airwave
Jun 17, 2026
Apr 29, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerabi...Show more
A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.Show less
1Avaya
1Equinox Conferencing
Jun 17, 2026
Apr 28, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
An XML External Entities (XXE) vulnerability in Media Server component of Avaya Equinox Conferencing could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system o...Show more
An XML External Entities (XXE) vulnerability in Media Server component of Avaya Equinox Conferencing could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system or even potentially lead to a denial of service. The affected versions of Avaya Equinox Conferencing includes all 9.x versions before 9.1.11. Equinox Conferencing is now offered as Avaya Meetings Server.Show less
1Arubanetworks
1Airwave
Jun 17, 2026
Apr 28, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerabi...Show more
A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.Show less
1Arubanetworks
1Airwave
Jun 17, 2026
Apr 28, 2021
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerabi...Show more
A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.Show less
1Avaya
1Callback Assist
Jun 17, 2026
Apr 23, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An XML External Entities (XXE)vulnerability in Callback Assist could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The affected versions of Callback Assi...Show more
An XML External Entities (XXE)vulnerability in Callback Assist could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The affected versions of Callback Assist includes all 4.0.x versions before 4.7.1.1 Patch 7.Show less
1Avaya
1Aura Orchestration Designer
Jun 17, 2026
Apr 23, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An XML External Entities (XXE)vulnerability in the web-based user interface of Avaya Aura Orchestration Designer could allow an authenticated, remote attacker to gain read access to information that is stored on an affec...Show more
An XML External Entities (XXE)vulnerability in the web-based user interface of Avaya Aura Orchestration Designer could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The affected versions of Orchestration Designer includes all 7.x versions before 7.2.3.Show less
1Fusionauth
1Saml V2
Jun 17, 2026
Apr 22, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFromBytes uses javax.xml.parsers.DocumentBuilderFactory unsafely.
1Jenkins
1Config File Provider
Jun 17, 2026
Apr 21, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.