CWE-611
Improper Restriction of XML External Entity Reference
Description
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-221
CVEs mapped to this weakness (1,331)
page 30 of 67| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-39239 | Hig | 0.49 | 7.5 | 0.04 | Sep 16, 2021 | A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including exposing the contents of local files to a remote server. | ||
| CVE-2021-40356 | Hig | 0.49 | 7.5 | 0.01 | Sep 14, 2021 | A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The application contains a XML External Entity Injection… | ||
| CVE-2021-1630 | Hig | 0.49 | 7.5 | 0.01 | Aug 5, 2021 | XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fabric, Pivotal Cloud Foundry, Private Cloud Edition, and on-premise customers. | ||
| CVE-2021-22523 | Hig | 0.49 | 7.6 | 0.01 | Jul 22, 2021 | XML External Entity vulnerability in Micro Focus Verastream Host Integrator, affecting version 7.8 Update 1 and earlier versions. The vulnerability could allow the control of web browser and hijacking user sessions. | ||
| CVE-2012-1102 | Hig | 0.49 | 7.5 | 0.01 | Jul 9, 2021 | It was discovered that the XML::Atom Perl module before version 0.39 did not disable external entities when parsing XML from potentially untrusted sources. This may allow attackers to gain read access to otherwise protected resources, depending on how the library is used. | ||
| CVE-2021-25951 | Hig | 0.49 | 7.5 | 0.01 | Jun 30, 2021 | XXE vulnerability in 'XML2Dict' version 0.2.2 allows an attacker to cause a denial of service. | ||
| CVE-2021-22140 | Hig | 0.49 | 7.5 | 0.01 | May 13, 2021 | Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an attacker whose website is being crawled by App Search could craft a malicious sitemap.xml to traverse… | ||
| CVE-2021-30006 | Hig | 0.49 | 7.5 | 0.01 | May 11, 2021 | In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure. | ||
| CVE-2021-21642 | Hig | 0.49 | 8.1 | 0.38 | Apr 21, 2021 | Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | ||
| CVE-2021-29447 | Hig | 0.49 | 7.1 | 0.86 | Apr 15, 2021 | Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful… | ||
| CVE-2020-6590 | Hig | 0.49 | 7.5 | 0.01 | Apr 8, 2021 | Forcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to information disclosure. | ||
| CVE-2021-28110 | Hig | 0.49 | 7.5 | 0.01 | Mar 19, 2021 | /exec in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a vulnerability in its XML parser. | ||
| CVE-2021-27184 | Hig | 0.49 | 7.5 | 0.02 | Feb 11, 2021 | Pelco Digital Sentry Server 7.18.72.11464 has an XML External Entity vulnerability (exploitable via the DTD parameter entities technique), resulting in disclosure and retrieval of arbitrary data on the affected node via an out-of-band (OOB) attack. The vulnerability is triggered… | ||
| CVE-2020-24454 | Hig | 0.49 | 7.5 | 0.01 | Nov 12, 2020 | Improper Restriction of XML External Entity Reference in subsystem forIntel(R) Quartus(R) Prime Pro Edition before version 20.3 and Intel(R) Quartus(R) Prime Standard Edition before version 20.2 may allow unauthenticated user to potentially enable information disclosure via… | ||
| CVE-2020-25186 | Hig | 0.49 | 7.5 | 0.01 | Oct 22, 2020 | An XXE vulnerability exists within LeviStudioU Release Build 2019-09-21 and prior when processing parameter entities, which may allow file disclosure. | ||
| CVE-2020-4643 | Hig | 0.49 | 7.5 | 0.03 | Sep 21, 2020 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information. IBM X-Force ID: 185590. | ||
| CVE-2020-14029 | Hig | 0.49 | 7.5 | 0.01 | Sep 18, 2020 | An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The RSS To SMS module processes XML files in an unsafe manner. This opens the application to an XML External Entity attack that can be used to perform SSRF or read arbitrary local files. | ||
| CVE-2020-5602 | Hig | 0.49 | 7.5 | 0.01 | Jun 30, 2020 | Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier, GX… | ||
| CVE-2020-14940 | Hig | 0.49 | 7.5 | 0.04 | Jun 23, 2020 | An issue was discovered in io/gpx/GPXDocumentReader.java in TuxGuitar 1.5.4. It uses misconfigured XML parsers, leading to XXE while loading GP6 (.gpx) and GP7 (.gp) tablature files. | ||
| CVE-2020-2012 | Hig | 0.49 | 7.5 | 0.02 | May 13, 2020 | Improper restriction of XML external entity reference ('XXE') vulnerability in Palo Alto Networks Panorama management service allows remote unauthenticated attackers with network access to the Panorama management interface to read arbitrary files on the system. This issue… |
- risk 0.49cvss 7.5epss 0.04
A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including exposing the contents of local files to a remote server.
- risk 0.49cvss 7.5epss 0.01
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The application contains a XML External Entity Injection…
- risk 0.49cvss 7.5epss 0.01
XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fabric, Pivotal Cloud Foundry, Private Cloud Edition, and on-premise customers.
- risk 0.49cvss 7.6epss 0.01
XML External Entity vulnerability in Micro Focus Verastream Host Integrator, affecting version 7.8 Update 1 and earlier versions. The vulnerability could allow the control of web browser and hijacking user sessions.
- risk 0.49cvss 7.5epss 0.01
It was discovered that the XML::Atom Perl module before version 0.39 did not disable external entities when parsing XML from potentially untrusted sources. This may allow attackers to gain read access to otherwise protected resources, depending on how the library is used.
- risk 0.49cvss 7.5epss 0.01
XXE vulnerability in 'XML2Dict' version 0.2.2 allows an attacker to cause a denial of service.
- risk 0.49cvss 7.5epss 0.01
Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an attacker whose website is being crawled by App Search could craft a malicious sitemap.xml to traverse…
- risk 0.49cvss 7.5epss 0.01
In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.
- risk 0.49cvss 8.1epss 0.38
Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- risk 0.49cvss 7.1epss 0.86
Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful…
- risk 0.49cvss 7.5epss 0.01
Forcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to information disclosure.
- risk 0.49cvss 7.5epss 0.01
/exec in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a vulnerability in its XML parser.
- risk 0.49cvss 7.5epss 0.02
Pelco Digital Sentry Server 7.18.72.11464 has an XML External Entity vulnerability (exploitable via the DTD parameter entities technique), resulting in disclosure and retrieval of arbitrary data on the affected node via an out-of-band (OOB) attack. The vulnerability is triggered…
- risk 0.49cvss 7.5epss 0.01
Improper Restriction of XML External Entity Reference in subsystem forIntel(R) Quartus(R) Prime Pro Edition before version 20.3 and Intel(R) Quartus(R) Prime Standard Edition before version 20.2 may allow unauthenticated user to potentially enable information disclosure via…
- risk 0.49cvss 7.5epss 0.01
An XXE vulnerability exists within LeviStudioU Release Build 2019-09-21 and prior when processing parameter entities, which may allow file disclosure.
- risk 0.49cvss 7.5epss 0.03
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information. IBM X-Force ID: 185590.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The RSS To SMS module processes XML files in an unsafe manner. This opens the application to an XML External Entity attack that can be used to perform SSRF or read arbitrary local files.
- risk 0.49cvss 7.5epss 0.01
Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier, GX…
- risk 0.49cvss 7.5epss 0.04
An issue was discovered in io/gpx/GPXDocumentReader.java in TuxGuitar 1.5.4. It uses misconfigured XML parsers, leading to XXE while loading GP6 (.gpx) and GP7 (.gp) tablature files.
- risk 0.49cvss 7.5epss 0.02
Improper restriction of XML external entity reference ('XXE') vulnerability in Palo Alto Networks Panorama management service allows remote unauthenticated attackers with network access to the Panorama management interface to read arbitrary files on the system. This issue…