CWE-611
Improper Restriction of XML External Entity Reference
Description
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-221
CVEs mapped to this weakness (1,372)
page 30 of 69| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-31447 | Hig | 0.49 | 7.5 | 0.01 | Jun 14, 2022 | An XML external entity (XXE) injection vulnerability in Magicpin v3.4 allows attackers to access sensitive database information via a crafted SVG file. | ||
| CVE-2022-31261 | Hig | 0.49 | 7.5 | 0.01 | May 24, 2022 | An XXE issue was discovered in Morpheus through 5.2.16 and 5.4.x through 5.4.4. A successful attack requires a SAML identity provider to be configured. In order to exploit the vulnerability, the attacker must know the unique SAML callback ID of the configured identity source. A… | ||
| CVE-2022-29801 | Hig | 0.49 | 7.5 | 0.01 | May 20, 2022 | A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.13), Teamcenter V13.0 (All versions < V13.0.0.9). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application server… | ||
| CVE-2021-27777 | Hig | 0.49 | 7.5 | 0.01 | May 12, 2022 | XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation. Attackers can exploit this vulnerability to manipulate XML content and inject malicious external entity references. | ||
| CVE-2022-29265 | Hig | 0.49 | 7.5 | 0.03 | Apr 30, 2022 | Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content Viewer service attempts to resolve XML External Entity references when viewing formatted XML files. The following Processors… | ||
| CVE-2021-44477 | Hig | 0.49 | 7.5 | 0.01 | Mar 25, 2022 | GE Gas Power ToolBoxST Version v04.07.05C suffers from an XML external entity (XXE) vulnerability using the DTD parameter entities technique that could result in disclosure and retrieval of arbitrary data on the affected node via an out-of-band (OOB) attack. The vulnerability is… | ||
| CVE-2022-21205 | Hig | 0.49 | 7.5 | 0.01 | Feb 9, 2022 | Improper restriction of XML external entity reference in DSP Builder Pro for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an unauthenticated user to potentially enable information disclosure via network access. | ||
| CVE-2021-20838 | Hig | 0.49 | 7.5 | 0.02 | Nov 1, 2021 | Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a denial of service (DoS) condition by processing a specially crafted XML document. | ||
| CVE-2020-19954 | Hig | 0.49 | 7.5 | 0.01 | Oct 14, 2021 | An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files. | ||
| CVE-2021-35496 | Hig | 0.49 | 7.5 | 0.01 | Oct 12, 2021 | The XMLA Connections component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO… | ||
| CVE-2021-40500 | Hig | 0.49 | 7.5 | 0.01 | Oct 12, 2021 | SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated attacker to exploit missing XML validations at endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation… | ||
| CVE-2021-41770 | Hig | 0.49 | 7.5 | 0.01 | Oct 7, 2021 | Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure. | ||
| CVE-2021-39239 | Hig | 0.49 | 7.5 | 0.04 | Sep 16, 2021 | A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including exposing the contents of local files to a remote server. | ||
| CVE-2021-40356 | Hig | 0.49 | 7.5 | 0.01 | Sep 14, 2021 | A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The application contains a XML External Entity Injection… | ||
| CVE-2021-1630 | Hig | 0.49 | 7.5 | 0.01 | Aug 5, 2021 | XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fabric, Pivotal Cloud Foundry, Private Cloud Edition, and on-premise customers. | ||
| CVE-2021-22523 | Hig | 0.49 | 7.6 | 0.01 | Jul 22, 2021 | XML External Entity vulnerability in Micro Focus Verastream Host Integrator, affecting version 7.8 Update 1 and earlier versions. The vulnerability could allow the control of web browser and hijacking user sessions. | ||
| CVE-2021-25951 | Hig | 0.49 | 7.5 | 0.01 | Jun 30, 2021 | XXE vulnerability in 'XML2Dict' version 0.2.2 allows an attacker to cause a denial of service. | ||
| CVE-2021-22140 | Hig | 0.49 | 7.5 | 0.01 | May 13, 2021 | Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an attacker whose website is being crawled by App Search could craft a malicious sitemap.xml to traverse… | ||
| CVE-2021-30006 | Hig | 0.49 | 7.5 | 0.01 | May 11, 2021 | In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure. | ||
| CVE-2021-21642 | Hig | 0.49 | 8.1 | 0.38 | Apr 21, 2021 | Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
- risk 0.49cvss 7.5epss 0.01
An XML external entity (XXE) injection vulnerability in Magicpin v3.4 allows attackers to access sensitive database information via a crafted SVG file.
- risk 0.49cvss 7.5epss 0.01
An XXE issue was discovered in Morpheus through 5.2.16 and 5.4.x through 5.4.4. A successful attack requires a SAML identity provider to be configured. In order to exploit the vulnerability, the attacker must know the unique SAML callback ID of the configured identity source. A…
- risk 0.49cvss 7.5epss 0.01
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.13), Teamcenter V13.0 (All versions < V13.0.0.9). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application server…
- risk 0.49cvss 7.5epss 0.01
XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation. Attackers can exploit this vulnerability to manipulate XML content and inject malicious external entity references.
- risk 0.49cvss 7.5epss 0.03
Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content Viewer service attempts to resolve XML External Entity references when viewing formatted XML files. The following Processors…
- risk 0.49cvss 7.5epss 0.01
GE Gas Power ToolBoxST Version v04.07.05C suffers from an XML external entity (XXE) vulnerability using the DTD parameter entities technique that could result in disclosure and retrieval of arbitrary data on the affected node via an out-of-band (OOB) attack. The vulnerability is…
- risk 0.49cvss 7.5epss 0.01
Improper restriction of XML external entity reference in DSP Builder Pro for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an unauthenticated user to potentially enable information disclosure via network access.
- risk 0.49cvss 7.5epss 0.02
Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a denial of service (DoS) condition by processing a specially crafted XML document.
- risk 0.49cvss 7.5epss 0.01
An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files.
- risk 0.49cvss 7.5epss 0.01
The XMLA Connections component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO…
- risk 0.49cvss 7.5epss 0.01
SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated attacker to exploit missing XML validations at endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation…
- risk 0.49cvss 7.5epss 0.01
Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.
- risk 0.49cvss 7.5epss 0.04
A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including exposing the contents of local files to a remote server.
- risk 0.49cvss 7.5epss 0.01
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The application contains a XML External Entity Injection…
- risk 0.49cvss 7.5epss 0.01
XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fabric, Pivotal Cloud Foundry, Private Cloud Edition, and on-premise customers.
- risk 0.49cvss 7.6epss 0.01
XML External Entity vulnerability in Micro Focus Verastream Host Integrator, affecting version 7.8 Update 1 and earlier versions. The vulnerability could allow the control of web browser and hijacking user sessions.
- risk 0.49cvss 7.5epss 0.01
XXE vulnerability in 'XML2Dict' version 0.2.2 allows an attacker to cause a denial of service.
- risk 0.49cvss 7.5epss 0.01
Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an attacker whose website is being crawled by App Search could craft a malicious sitemap.xml to traverse…
- risk 0.49cvss 7.5epss 0.01
In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.
- risk 0.49cvss 8.1epss 0.38
Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.