VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,372)

page 21 of 69
  • CVE-2021-25165HigApr 28, 2021
    risk 0.53cvss 8.1epss 0.01

    A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

  • CVE-2020-7036HigApr 23, 2021
    risk 0.53cvss 8.1epss 0.01

    An XML External Entities (XXE)vulnerability in Callback Assist could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The affected versions of Callback Assist includes all 4.0.x versions before 4.7.1.1 Patch 7.

  • CVE-2020-7035HigApr 23, 2021
    risk 0.53cvss 8.1epss 0.01

    An XML External Entities (XXE)vulnerability in the web-based user interface of Avaya Aura Orchestration Designer could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The affected versions of Orchestration Designer…

  • CVE-2021-22498HigJan 19, 2021
    risk 0.53cvss 8.1epss 0.01

    XML External Entity Injection vulnerability in Micro Focus Application Lifecycle Management (Previously known as Quality Center) product. The vulnerability affects versions 12.x, 12.60 Patch 5 and earlier, 15.0.1 Patch 2 and earlier and 15.5. The vulnerability could be exploited…

  • CVE-2020-4772HigOct 12, 2020
    risk 0.53cvss 8.1epss 0.01

    An XML External Entity Injection (XXE) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. A remote attacker could exploit this vulnerability to expose sensitive information, denial of service, server side request forgery or consume memory resources.…

  • CVE-2020-4481HigAug 5, 2020
    risk 0.53cvss 8.2epss 0.02

    IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force…

  • CVE-2020-14204HigJun 22, 2020
    risk 0.53cvss 8.2epss 0.02

    In WebFOCUS Business Intelligence 8.0 (SP6), the administration portal allows remote attackers to read arbitrary local files or forge server-side HTTP requests via a crafted HTTP request to /ibi_apps/WFServlet.cfg because XML external entity injection is possible. This is…

  • CVE-2019-4391HigApr 7, 2020
    risk 0.53cvss 8.2epss 0.01

    HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data

  • CVE-2019-10466HigOct 23, 2019
    risk 0.53cvss 8.1epss 0.01

    An XML external entities (XXE) vulnerability in Jenkins 360 FireLine Plugin allows attackers with Overall/Read access to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins agent, server-side request forgery, or denial-of-service…

  • CVE-2019-4424HigAug 20, 2019
    risk 0.53cvss 8.2epss 0.02

    IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, and 19.0.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory…

  • CVE-2019-4340HigAug 20, 2019
    risk 0.53cvss 8.2epss 0.02

    IBM Security Guardium Big Data Intelligence 4.0 (SonarG) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID:…

  • CVE-2019-4419HigAug 20, 2019
    risk 0.53cvss 8.2epss 0.02

    IBM Intelligent Operations Center V5.1.0 through V5.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 162737.

  • CVE-2019-10266HigJul 26, 2019
    risk 0.53cvss 7.5epss 0.09

    An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When sending an out-of-bounds XML document to a URL, it is possible to read the file structure and even the content of files without authentication.

  • CVE-2019-13031HigJun 28, 2019
    risk 0.53cvss 8.1epss 0.02

    LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and has a "deny all" rule.

  • CVE-2019-7722HigFeb 11, 2019
    risk 0.53cvss 8.1epss 0.01

    PMD 5.8.1 and earlier processes XML external entities in ruleset files it parses as part of the analysis process, allowing attackers tampering it (either by direct modification or MITM attacks when using remote rulesets) to perform information disclosure, denial of service, or…

  • CVE-2018-7063HigDec 7, 2018
    risk 0.53cvss 8.1epss 0.01

    In Aruba ClearPass, disabled API admins can still perform read/write operations. In certain circumstances, API admins in ClearPass which have been disabled may still be able to perform read/write operations on parts of the XML API. This can lead to unauthorized access to the API…

  • CVE-2018-12585HigSep 14, 2018
    risk 0.53cvss 8.2epss 0.02

    An XXE vulnerability in the OPC UA Java and .NET Legacy Stack can allow remote attackers to trigger a denial of service.

  • CVE-2018-11758HigAug 22, 2018
    risk 0.53cvss 8.1epss 0.03

    This affects Apache Cayenne 4.1.M1, 3.2.M1, 4.0.M2 to 4.0.M5, 4.0.B1, 4.0.B2, 4.0.RC1, 3.1, 3.1.1, 3.1.2. CayenneModeler is a desktop GUI tool shipped with Apache Cayenne and intended for editing Cayenne ORM models stored as XML files. If an attacker tricks a user of…

  • CVE-2018-11048HigAug 10, 2018
    risk 0.53cvss 8.1epss 0.02

    Dell EMC Data Protection Advisor, versions 6.2, 6,3, 6.4, 6.5 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 contain a XML External Entity (XXE) Injection vulnerability in the REST API. An authenticated remote malicious user could potentially exploit…

  • CVE-2017-16349HigAug 2, 2018
    risk 0.53cvss 8.1epss 0.01

    An exploitable XML external entity vulnerability exists in the reporting functionality of SAP BPC. A specially crafted XML request can cause an XML external entity to be referenced, resulting in information disclosure and potential denial of service. An attacker can issue…