CWE-611
1,268 CVEs • Abstraction: Base
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVEs (1,268)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-19 Unauthenticated XXE in /management/UdpHttpService issue. |
1Ibm 1Security Key Lifecycle Manager Nov 21, 2024 Oct 15, 2018 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive inf...Show more |
IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or co...Show more |
In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against XML attacks. This mechanism is exclusively when the developer uses the E...Show more |
1Microsoft 1Sql Server Management Studio Jun 17, 2026 Oct 10, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious XML content containing a reference to an external entity, aka "SQL Server Management Studio Informati...Show more |
1Microsoft 1Sql Server Management Studio Jun 17, 2026 Oct 10, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XMLA file containing a reference to an external entity, aka "SQL Server Management Studio Informati...Show more |
1Microsoft 1Sql Server Management Studio Jun 17, 2026 Oct 10, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XEL file containing a reference to an external entity, aka "SQL Server Management Studio Informatio...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Oct 10, 2018 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windo...Show more |
In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() after each parse, which, for Xerces2 parsers, as per the documentation, removes...Show more |
An XXE vulnerability in LeviStudioU, Versions 1.8.29 and 1.8.44 can be exploited when the application processes specially crafted project XML files. |
1We Con 2Pi Studio Pi Studio HmiNov 21, 2024 Oct 8, 2018 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 In WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior when parsing project files, the XMLParser that ships with Wecon PIStudio is vulnerable to a XML external entity...Show more |
1Cisco 1Secure Access Control Server Solution Engine Nov 21, 2024 Oct 5, 2018 N/A· v4 5.7 MEDIUM· v3 3.5 LOW· v2 A vulnerability in the web-based UI of Cisco Secure Access Control Server could allow an authenticated, remote attacker to gain read access to certain information in an affected system. The vulnerability is due to improp...Show more |
1Suse 1Subscription Management Tool Nov 21, 2024 Oct 4, 2018 N/A· v4 8.1 HIGH· v3 6.4 MEDIUM· v2 A External Entity Reference ('XXE') vulnerability in SUSE Linux SMT allows remote attackers to read data from the server or cause DoS by referencing blocking elements. Affected releases are SUSE Linux SMT: versions prior...Show more |
1Ibm 2Platform Symphony Spectrum SymphonyNov 21, 2024 Sep 28, 2018 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vul...Show more |
1Informationbuilders 1Data Quality Suite Nov 21, 2024 Sep 26, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An XML External Entity (XXE) vulnerability exists in iWay Data Quality Suite Web Console 10.6.1.ga-2016-11-20. |
1Javamelody Project 1Javamelody Nov 21, 2024 Sep 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 JavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java. |
IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 are vulnerable to a XM...Show more |
1Ibm 1Rational Engineering Lifecycle Manager Nov 21, 2024 Sep 25, 2018 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability...Show more |
1Ibm 1Rational Engineering Lifecycle Manager Nov 21, 2024 Sep 25, 2018 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could expl...Show more |
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity is processed by a we...Show more |