VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,331)

page 29 of 67
  • CVE-2022-37189HigSep 7, 2022
    risk 0.49cvss 7.5epss 0.01

    DDMAL MEI2Volpiano 0.8.2 is vulnerable to XML External Entity (XXE), leading to a Denial of Service. This occurs due to the usage of the unsafe 'xml.etree' library to parse untrusted XML input.

  • CVE-2022-0217HigAug 26, 2022
    risk 0.49cvss 7.5epss 0.05

    It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML data. Given suitable attacker input, this results in expansion of recursive entity references from DTDs (CWE-776). In addition,…

  • CVE-2020-21641HigAug 15, 2022
    risk 0.49cvss 7.5epss 0.04

    Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary files, enumerate folders and scan internal ports via crafted XML license file.

  • CVE-2022-1704HigAug 5, 2022
    risk 0.49cvss 7.6epss 0.01

    Due to an XML external entity reference, the software parses XML in the backup/restore functionality without XML security flags, which may lead to a XXE attack while restoring the backup.

  • CVE-2022-32458HigJul 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Digiwin BPM has a XML External Entity Injection (XXE) vulnerability due to insufficient validation for user input. An unauthenticated remote attacker can perform XML injection attack to access arbitrary system files.

  • CVE-2022-35168HigJul 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Due to improper input sanitization of XML input in SAP Business One - version 10.0, an attacker can perform a denial-of-service attack rendering the system temporarily inoperative.

  • CVE-2021-40510HigJun 21, 2022
    risk 0.49cvss 7.5epss 0.01

    XML eXternal Entity (XXE) in OBDA systems’ Mastro 1.0 allows remote attackers to read system files via custom DTDs.

  • CVE-2022-32285HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in Mendix SAML Module (Mendix 7 compatible) (All versions < V1.16.6), Mendix SAML Module (Mendix 8 compatible) (All versions < V2.2.2), Mendix SAML Module (Mendix 9 compatible) (All versions < V3.2.3). The affected module is vulnerable to XML…

  • CVE-2022-31447HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An XML external entity (XXE) injection vulnerability in Magicpin v3.4 allows attackers to access sensitive database information via a crafted SVG file.

  • CVE-2022-31261HigMay 24, 2022
    risk 0.49cvss 7.5epss 0.01

    An XXE issue was discovered in Morpheus through 5.2.16 and 5.4.x through 5.4.4. A successful attack requires a SAML identity provider to be configured. In order to exploit the vulnerability, the attacker must know the unique SAML callback ID of the configured identity source. A…

  • CVE-2022-29801HigMay 20, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.13), Teamcenter V13.0 (All versions < V13.0.0.9). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application server…

  • CVE-2021-27777HigMay 12, 2022
    risk 0.49cvss 7.5epss 0.01

    XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation. Attackers can exploit this vulnerability to manipulate XML content and inject malicious external entity references.

  • CVE-2022-29265HigApr 30, 2022
    risk 0.49cvss 7.5epss 0.03

    Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content Viewer service attempts to resolve XML External Entity references when viewing formatted XML files. The following Processors…

  • CVE-2021-44477HigMar 25, 2022
    risk 0.49cvss 7.5epss 0.01

    GE Gas Power ToolBoxST Version v04.07.05C suffers from an XML external entity (XXE) vulnerability using the DTD parameter entities technique that could result in disclosure and retrieval of arbitrary data on the affected node via an out-of-band (OOB) attack. The vulnerability is…

  • CVE-2022-21205HigFeb 9, 2022
    risk 0.49cvss 7.5epss 0.01

    Improper restriction of XML external entity reference in DSP Builder Pro for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an unauthenticated user to potentially enable information disclosure via network access.

  • CVE-2021-20838HigNov 1, 2021
    risk 0.49cvss 7.5epss 0.01

    Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a denial of service (DoS) condition by processing a specially crafted XML document.

  • CVE-2020-19954HigOct 14, 2021
    risk 0.49cvss 7.5epss 0.01

    An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files.

  • CVE-2021-35496HigOct 12, 2021
    risk 0.49cvss 7.5epss 0.01

    The XMLA Connections component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO…

  • CVE-2021-40500HigOct 12, 2021
    risk 0.49cvss 7.5epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated attacker to exploit missing XML validations at endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation…

  • CVE-2021-41770HigOct 7, 2021
    risk 0.49cvss 7.5epss 0.01

    Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.