VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,331)

page 31 of 67
  • CVE-2020-10629HigApr 9, 2020
    risk 0.49cvss 7.5epss 0.01

    WebAccess/NMS (versions prior to 3.0.2) does not sanitize XML input. Specially crafted XML input could allow an attacker to read sensitive files.

  • CVE-2019-20191HigMar 16, 2020
    risk 0.49cvss 7.5epss 0.01

    Oxygen XML Editor 21.1.1 allows XXE to read any file.

  • CVE-2020-9044HigMar 10, 2020
    risk 0.49cvss 7.5epss 0.01

    XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or harvesting of ASCII server files. This affects Johnson Controls' Metasys Application and Data Server (ADS, ADS-Lite) versions 10.1 and prior; Metasys…

  • CVE-2020-2108HigJan 29, 2020
    risk 0.49cvss 7.6epss 0.01

    Jenkins WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XXE attacks which can be exploited by a user with Job/Configure permissions.

  • CVE-2015-1811HigJan 15, 2020
    risk 0.49cvss 7.5epss 0.01

    XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via a crafted XML document.

  • CVE-2015-1809HigJan 15, 2020
    risk 0.49cvss 7.5epss 0.01

    XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via an XPath query.

  • CVE-2019-18412HigJan 15, 2020
    risk 0.49cvss 7.5epss 0.01

    JetBrains IDETalk plugin before version 193.4099.10 allows XXE

  • CVE-2019-19998HigDec 26, 2019
    risk 0.49cvss 7.5epss 0.01

    Xiuno BBS 4.0 allows XXE via plugin/xn_wechat_public/route/token.php.

  • CVE-2019-18227HigOct 31, 2019
    risk 0.49cvss 7.5epss 0.03

    Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. XXE vulnerabilities exist that may allow disclosure of sensitive data.

  • CVE-2017-15725HigOct 28, 2019
    risk 0.49cvss 7.5epss 0.01

    An XML External Entity Injection vulnerability exists in Dzone AnswerHub.

  • CVE-2019-8087HigOct 25, 2019
    risk 0.49cvss 7.5epss 0.04

    Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2019-8082HigOct 25, 2019
    risk 0.49cvss 7.5epss 0.03

    Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2019-6179HigSep 3, 2019
    risk 0.49cvss 7.5epss 0.01

    An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) prior to version 2.5.0 , Lenovo XClarity Integrator (LXCI) for Microsoft System Center prior to version 7.7.0, and Lenovo XClarity Integrator (LXCI) for VMWare vCenter…

  • CVE-2019-14258HigAug 21, 2019
    risk 0.49cvss 7.5epss 0.02

    The XML-RPC subsystem in Zenoss 2.5.3 allows XXE attacks that lead to unauthenticated information disclosure via port 9988.

  • CVE-2019-15160HigAug 19, 2019
    risk 0.49cvss 7.5epss 0.02

    The SweetXml (aka sweet_xml) package through 0.6.6 for Erlang and Elixir allows attackers to cause a denial of service (resource consumption) via an XML entity expansion attack with an inline DTD.

  • CVE-2019-1057HigAug 14, 2019
    risk 0.49cvss 7.5epss 0.03

    A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exploited the vulnerability could run malicious code remotely to take control of the user’s system. To exploit the vulnerability,…

  • CVE-2019-13176HigAug 8, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2. The Content.MainForm.wgx component is affected by XXE via a crafted XML document in POST data. There is potential to use this for SSRF (reading local files, outbound HTTP,…

  • CVE-2018-14383HigAug 7, 2019
    risk 0.49cvss 7.5epss 0.01

    The Transition Technologies "The Scheduler" app 5.1.3 for Jira allows XXE due to a weakly configured/parameterized XML parser. It was fixed in the versions 5.2.1 and 3.3.7

  • CVE-2019-7847HigJul 18, 2019
    risk 0.49cvss 7.5epss 0.03

    Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper Restriction of XML External Entity Reference ('XXE') vulnerability. Successful exploitation could lead to Arbitrary read access to the file system in the context of the current user.

  • CVE-2019-11392HigJun 21, 2019
    risk 0.49cvss 7.5epss 0.02

    BlogEngine.NET 3.3.7 and earlier allows XXE via an apml file to syndication.axd.