VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,331)

page 30 of 67
  • CVE-2021-39239HigSep 16, 2021
    risk 0.49cvss 7.5epss 0.04

    A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including exposing the contents of local files to a remote server.

  • CVE-2021-40356HigSep 14, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The application contains a XML External Entity Injection…

  • CVE-2021-1630HigAug 5, 2021
    risk 0.49cvss 7.5epss 0.01

    XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fabric, Pivotal Cloud Foundry, Private Cloud Edition, and on-premise customers.

  • CVE-2021-22523HigJul 22, 2021
    risk 0.49cvss 7.6epss 0.01

    XML External Entity vulnerability in Micro Focus Verastream Host Integrator, affecting version 7.8 Update 1 and earlier versions. The vulnerability could allow the control of web browser and hijacking user sessions.

  • CVE-2012-1102HigJul 9, 2021
    risk 0.49cvss 7.5epss 0.01

    It was discovered that the XML::Atom Perl module before version 0.39 did not disable external entities when parsing XML from potentially untrusted sources. This may allow attackers to gain read access to otherwise protected resources, depending on how the library is used.

  • CVE-2021-25951HigJun 30, 2021
    risk 0.49cvss 7.5epss 0.01

    XXE vulnerability in 'XML2Dict' version 0.2.2 allows an attacker to cause a denial of service.

  • CVE-2021-22140HigMay 13, 2021
    risk 0.49cvss 7.5epss 0.01

    Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an attacker whose website is being crawled by App Search could craft a malicious sitemap.xml to traverse…

  • CVE-2021-30006HigMay 11, 2021
    risk 0.49cvss 7.5epss 0.01

    In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.

  • CVE-2021-21642HigApr 21, 2021
    risk 0.49cvss 8.1epss 0.38

    Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2021-29447HigApr 15, 2021
    risk 0.49cvss 7.1epss 0.86

    Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful…

  • CVE-2020-6590HigApr 8, 2021
    risk 0.49cvss 7.5epss 0.01

    Forcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to information disclosure.

  • CVE-2021-28110HigMar 19, 2021
    risk 0.49cvss 7.5epss 0.01

    /exec in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a vulnerability in its XML parser.

  • CVE-2021-27184HigFeb 11, 2021
    risk 0.49cvss 7.5epss 0.02

    Pelco Digital Sentry Server 7.18.72.11464 has an XML External Entity vulnerability (exploitable via the DTD parameter entities technique), resulting in disclosure and retrieval of arbitrary data on the affected node via an out-of-band (OOB) attack. The vulnerability is triggered…

  • CVE-2020-24454HigNov 12, 2020
    risk 0.49cvss 7.5epss 0.01

    Improper Restriction of XML External Entity Reference in subsystem forIntel(R) Quartus(R) Prime Pro Edition before version 20.3 and Intel(R) Quartus(R) Prime Standard Edition before version 20.2 may allow unauthenticated user to potentially enable information disclosure via…

  • CVE-2020-25186HigOct 22, 2020
    risk 0.49cvss 7.5epss 0.01

    An XXE vulnerability exists within LeviStudioU Release Build 2019-09-21 and prior when processing parameter entities, which may allow file disclosure.

  • CVE-2020-4643HigSep 21, 2020
    risk 0.49cvss 7.5epss 0.03

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information. IBM X-Force ID: 185590.

  • CVE-2020-14029HigSep 18, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The RSS To SMS module processes XML files in an unsafe manner. This opens the application to an XML External Entity attack that can be used to perform SSRF or read arbitrary local files.

  • CVE-2020-5602HigJun 30, 2020
    risk 0.49cvss 7.5epss 0.01

    Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier, GX…

  • CVE-2020-14940HigJun 23, 2020
    risk 0.49cvss 7.5epss 0.04

    An issue was discovered in io/gpx/GPXDocumentReader.java in TuxGuitar 1.5.4. It uses misconfigured XML parsers, leading to XXE while loading GP6 (.gpx) and GP7 (.gp) tablature files.

  • CVE-2020-2012HigMay 13, 2020
    risk 0.49cvss 7.5epss 0.02

    Improper restriction of XML external entity reference ('XXE') vulnerability in Palo Alto Networks Panorama management service allows remote unauthenticated attackers with network access to the Panorama management interface to read arbitrary files on the system. This issue…