VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,331)

page 18 of 67
  • CVE-2022-2131HigJul 25, 2022
    risk 0.55cvss 8.5epss 0.01

    OpenKM Community Edition in its 6.3.10 version and before was using XMLReader parser in XMLTextExtractor.java file without the required security flags, allowing an attacker to perform a XML external entity injection attack.

  • CVE-2020-27858HigJan 20, 2021
    risk 0.55cvss 7.5epss 0.74

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getNews method. Due to the improper restriction of…

  • CVE-2020-11991HigSep 11, 2020
    risk 0.55cvss 7.5epss 0.72

    When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server system.

  • CVE-2020-17408HigSep 10, 2020
    risk 0.55cvss 7.5epss 0.74

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the clpwebmc executable. Due to the improper…

  • CVE-2018-2392HigFeb 14, 2018
    risk 0.55cvss 7.5epss 0.41

    Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.

  • CVE-2025-66516HigDec 4, 2025
    risk 0.54cvss 8.4epss 0.79

    Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. This CVE covers the same…

  • CVE-2025-11700HigNov 12, 2025
    risk 0.54cvss 7.5epss 0.31

    N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure

  • CVE-2025-54445HigJul 23, 2025
    risk 0.54cvss 8.2epss 0.10

    Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Server Side Request Forgery.This issue affects MagicINFO 9 Server: less than 21.1080.0.

  • CVE-2024-53675HigNov 26, 2024
    risk 0.54cvss 7.3epss 0.84

    An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

  • CVE-2023-6721HigDec 13, 2023
    risk 0.54cvss 8.3epss 0.01

    An XEE vulnerability has been found in Repox, which allows a remote attacker to interfere with the application's XML data processing in the fileupload function, resulting in interaction between the attacker and the server's file system.

  • CVE-2020-4300HigJun 1, 2021
    risk 0.54cvss 8.2epss 0.04

    IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 176607.

  • CVE-2021-20454HigApr 21, 2021
    risk 0.54cvss 8.2epss 0.03

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196649.

  • CVE-2021-20453HigApr 20, 2021
    risk 0.54cvss 8.2epss 0.03

    IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196648.

  • CVE-2021-20353HigFeb 10, 2021
    risk 0.54cvss 8.2epss 0.05

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 194882.

  • CVE-2020-4949HigJan 26, 2021
    risk 0.54cvss 8.2epss 0.05

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192025.

  • CVE-2020-15419HigJul 28, 2020
    risk 0.54cvss 7.5epss 0.60

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Reporter_ImportLicense class. Due to the…

  • CVE-2020-4462HigJul 16, 2020
    risk 0.54cvss 8.2epss 0.03

    IBM Sterling External Authentication Server 6.0.1, 6.0.0, 2.4.3.2, and 2.4.2 and IBM Sterling Secure Proxy 6.0.1, 6.0.0, 3.4.3, and 3.4.2 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability…

  • CVE-2019-4513HigAug 26, 2019
    risk 0.54cvss 8.2epss 0.03

    IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force…

  • CVE-2019-4433HigAug 20, 2019
    risk 0.54cvss 8.2epss 0.04

    IBM InfoSphere Global Name Management 5.0 and 6.0 and IBM InfoSphere Identity Insight 8.1 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or…

  • CVE-2018-1000055HigFeb 9, 2018
    risk 0.54cvss 8.3epss 0.01

    Jenkins Android Lint Plugin 2.5 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service…