VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,372)

page 30 of 69
  • CVE-2022-31447HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An XML external entity (XXE) injection vulnerability in Magicpin v3.4 allows attackers to access sensitive database information via a crafted SVG file.

  • CVE-2022-31261HigMay 24, 2022
    risk 0.49cvss 7.5epss 0.01

    An XXE issue was discovered in Morpheus through 5.2.16 and 5.4.x through 5.4.4. A successful attack requires a SAML identity provider to be configured. In order to exploit the vulnerability, the attacker must know the unique SAML callback ID of the configured identity source. A…

  • CVE-2022-29801HigMay 20, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.13), Teamcenter V13.0 (All versions < V13.0.0.9). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application server…

  • CVE-2021-27777HigMay 12, 2022
    risk 0.49cvss 7.5epss 0.01

    XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation. Attackers can exploit this vulnerability to manipulate XML content and inject malicious external entity references.

  • CVE-2022-29265HigApr 30, 2022
    risk 0.49cvss 7.5epss 0.03

    Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content Viewer service attempts to resolve XML External Entity references when viewing formatted XML files. The following Processors…

  • CVE-2021-44477HigMar 25, 2022
    risk 0.49cvss 7.5epss 0.01

    GE Gas Power ToolBoxST Version v04.07.05C suffers from an XML external entity (XXE) vulnerability using the DTD parameter entities technique that could result in disclosure and retrieval of arbitrary data on the affected node via an out-of-band (OOB) attack. The vulnerability is…

  • CVE-2022-21205HigFeb 9, 2022
    risk 0.49cvss 7.5epss 0.01

    Improper restriction of XML external entity reference in DSP Builder Pro for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an unauthenticated user to potentially enable information disclosure via network access.

  • CVE-2021-20838HigNov 1, 2021
    risk 0.49cvss 7.5epss 0.02

    Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a denial of service (DoS) condition by processing a specially crafted XML document.

  • CVE-2020-19954HigOct 14, 2021
    risk 0.49cvss 7.5epss 0.01

    An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files.

  • CVE-2021-35496HigOct 12, 2021
    risk 0.49cvss 7.5epss 0.01

    The XMLA Connections component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO…

  • CVE-2021-40500HigOct 12, 2021
    risk 0.49cvss 7.5epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated attacker to exploit missing XML validations at endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation…

  • CVE-2021-41770HigOct 7, 2021
    risk 0.49cvss 7.5epss 0.01

    Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.

  • CVE-2021-39239HigSep 16, 2021
    risk 0.49cvss 7.5epss 0.04

    A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including exposing the contents of local files to a remote server.

  • CVE-2021-40356HigSep 14, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The application contains a XML External Entity Injection…

  • CVE-2021-1630HigAug 5, 2021
    risk 0.49cvss 7.5epss 0.01

    XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fabric, Pivotal Cloud Foundry, Private Cloud Edition, and on-premise customers.

  • CVE-2021-22523HigJul 22, 2021
    risk 0.49cvss 7.6epss 0.01

    XML External Entity vulnerability in Micro Focus Verastream Host Integrator, affecting version 7.8 Update 1 and earlier versions. The vulnerability could allow the control of web browser and hijacking user sessions.

  • CVE-2021-25951HigJun 30, 2021
    risk 0.49cvss 7.5epss 0.01

    XXE vulnerability in 'XML2Dict' version 0.2.2 allows an attacker to cause a denial of service.

  • CVE-2021-22140HigMay 13, 2021
    risk 0.49cvss 7.5epss 0.01

    Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an attacker whose website is being crawled by App Search could craft a malicious sitemap.xml to traverse…

  • CVE-2021-30006HigMay 11, 2021
    risk 0.49cvss 7.5epss 0.01

    In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.

  • CVE-2021-21642HigApr 21, 2021
    risk 0.49cvss 8.1epss 0.38

    Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.