CWE-611
Improper Restriction of XML External Entity Reference
Description
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-221
CVEs mapped to this weakness (1,372)
page 32 of 69| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-15725 | Hig | 0.49 | 7.5 | 0.01 | Oct 28, 2019 | An XML External Entity Injection vulnerability exists in Dzone AnswerHub. | ||
| CVE-2019-8087 | Hig | 0.49 | 7.5 | 0.04 | Oct 25, 2019 | Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure. | ||
| CVE-2019-8082 | Hig | 0.49 | 7.5 | 0.03 | Oct 25, 2019 | Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure. | ||
| CVE-2019-6179 | Hig | 0.49 | 7.5 | 0.01 | Sep 3, 2019 | An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) prior to version 2.5.0 , Lenovo XClarity Integrator (LXCI) for Microsoft System Center prior to version 7.7.0, and Lenovo XClarity Integrator (LXCI) for VMWare vCenter… | ||
| CVE-2019-14258 | Hig | 0.49 | 7.5 | 0.02 | Aug 21, 2019 | The XML-RPC subsystem in Zenoss 2.5.3 allows XXE attacks that lead to unauthenticated information disclosure via port 9988. | ||
| CVE-2019-15160 | Hig | 0.49 | 7.5 | 0.02 | Aug 19, 2019 | The SweetXml (aka sweet_xml) package through 0.6.6 for Erlang and Elixir allows attackers to cause a denial of service (resource consumption) via an XML entity expansion attack with an inline DTD. | ||
| CVE-2019-1057 | Hig | 0.49 | 7.5 | 0.03 | Aug 14, 2019 | A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exploited the vulnerability could run malicious code remotely to take control of the user’s system. To exploit the vulnerability,… | ||
| CVE-2019-13176 | — | Hig | 0.49 | 7.5 | 0.02 | Aug 8, 2019 | An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2. The Content.MainForm.wgx component is affected by XXE via a crafted XML document in POST data. There is potential to use this for SSRF (reading local files, outbound HTTP,… | |
| CVE-2018-14383 | Hig | 0.49 | 7.5 | 0.01 | Aug 7, 2019 | The Transition Technologies "The Scheduler" app 5.1.3 for Jira allows XXE due to a weakly configured/parameterized XML parser. It was fixed in the versions 5.2.1 and 3.3.7 | ||
| CVE-2019-7847 | Hig | 0.49 | 7.5 | 0.03 | Jul 18, 2019 | Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper Restriction of XML External Entity Reference ('XXE') vulnerability. Successful exploitation could lead to Arbitrary read access to the file system in the context of the current user. | ||
| CVE-2019-11392 | Hig | 0.49 | 7.5 | 0.01 | Jun 21, 2019 | BlogEngine.NET 3.3.7 and earlier allows XXE via an apml file to syndication.axd. | ||
| CVE-2019-10718 | Hig | 0.49 | 7.5 | 0.02 | Jun 21, 2019 | BlogEngine.NET 3.3.7.0 and earlier allows XML External Entity Blind Injection, related to pingback.axd and BlogEngine.Core/Web/HttpHandlers/PingbackHandler.cs. | ||
| CVE-2019-3722 | Hig | 0.49 | 7.5 | 0.04 | Jun 6, 2019 | Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external entity (XXE) injection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to read arbitrary server system files by… | ||
| CVE-2019-8999 | Hig | 0.49 | 7.5 | 0.01 | Apr 18, 2019 | An XML External Entity vulnerability in the UEM Core of BlackBerry UEM version(s) earlier than 12.10.1a could allow an attacker to potentially gain read access to files on any system reachable by the UEM service account. | ||
| CVE-2019-10244 | Hig | 0.49 | 7.5 | 0.02 | Apr 9, 2019 | In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service (not part of the device distribution) could potentially be target of XXE attack due to an improper factory and parser… | ||
| CVE-2019-9761 | Hig | 0.49 | 7.5 | 0.01 | Mar 14, 2019 | An XXE issue was discovered in PHPSHE 1.7, which can be used to read any file in the system or scan the internal network without authentication. This occurs because of the call to wechat_getxml in include/plugin/payment/wechat/notify_url.php. | ||
| CVE-2018-20733 | Hig | 0.49 | 7.5 | 0.01 | Jan 17, 2019 | BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE. | ||
| CVE-2018-7837 | Hig | 0.49 | 7.5 | 0.01 | Dec 24, 2018 | An Improper Restriction of XML External Entity Reference ('XXE') vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow the software to resolve documents outside of the intended sphere of control, causing the software to embed incorrect… | ||
| CVE-2018-20157 | Hig | 0.49 | 7.5 | 0.02 | Dec 15, 2018 | The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zip) file, allowing attackers to read arbitrary files. | ||
| CVE-2018-17912 | Hig | 0.49 | 7.5 | 0.01 | Nov 2, 2018 | An XXE vulnerability exists in CASE Suite Versions 3.10 and prior when processing parameter entities, which may allow remote file disclosure. |
- risk 0.49cvss 7.5epss 0.01
An XML External Entity Injection vulnerability exists in Dzone AnswerHub.
- risk 0.49cvss 7.5epss 0.04
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
- risk 0.49cvss 7.5epss 0.03
Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
- risk 0.49cvss 7.5epss 0.01
An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) prior to version 2.5.0 , Lenovo XClarity Integrator (LXCI) for Microsoft System Center prior to version 7.7.0, and Lenovo XClarity Integrator (LXCI) for VMWare vCenter…
- risk 0.49cvss 7.5epss 0.02
The XML-RPC subsystem in Zenoss 2.5.3 allows XXE attacks that lead to unauthenticated information disclosure via port 9988.
- risk 0.49cvss 7.5epss 0.02
The SweetXml (aka sweet_xml) package through 0.6.6 for Erlang and Elixir allows attackers to cause a denial of service (resource consumption) via an XML entity expansion attack with an inline DTD.
- risk 0.49cvss 7.5epss 0.03
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exploited the vulnerability could run malicious code remotely to take control of the user’s system. To exploit the vulnerability,…
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2. The Content.MainForm.wgx component is affected by XXE via a crafted XML document in POST data. There is potential to use this for SSRF (reading local files, outbound HTTP,…
- risk 0.49cvss 7.5epss 0.01
The Transition Technologies "The Scheduler" app 5.1.3 for Jira allows XXE due to a weakly configured/parameterized XML parser. It was fixed in the versions 5.2.1 and 3.3.7
- risk 0.49cvss 7.5epss 0.03
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper Restriction of XML External Entity Reference ('XXE') vulnerability. Successful exploitation could lead to Arbitrary read access to the file system in the context of the current user.
- risk 0.49cvss 7.5epss 0.01
BlogEngine.NET 3.3.7 and earlier allows XXE via an apml file to syndication.axd.
- risk 0.49cvss 7.5epss 0.02
BlogEngine.NET 3.3.7.0 and earlier allows XML External Entity Blind Injection, related to pingback.axd and BlogEngine.Core/Web/HttpHandlers/PingbackHandler.cs.
- risk 0.49cvss 7.5epss 0.04
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external entity (XXE) injection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to read arbitrary server system files by…
- risk 0.49cvss 7.5epss 0.01
An XML External Entity vulnerability in the UEM Core of BlackBerry UEM version(s) earlier than 12.10.1a could allow an attacker to potentially gain read access to files on any system reachable by the UEM service account.
- risk 0.49cvss 7.5epss 0.02
In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service (not part of the device distribution) could potentially be target of XXE attack due to an improper factory and parser…
- risk 0.49cvss 7.5epss 0.01
An XXE issue was discovered in PHPSHE 1.7, which can be used to read any file in the system or scan the internal network without authentication. This occurs because of the call to wechat_getxml in include/plugin/payment/wechat/notify_url.php.
- risk 0.49cvss 7.5epss 0.01
BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE.
- risk 0.49cvss 7.5epss 0.01
An Improper Restriction of XML External Entity Reference ('XXE') vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow the software to resolve documents outside of the intended sphere of control, causing the software to embed incorrect…
- risk 0.49cvss 7.5epss 0.02
The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zip) file, allowing attackers to read arbitrary files.
- risk 0.49cvss 7.5epss 0.01
An XXE vulnerability exists in CASE Suite Versions 3.10 and prior when processing parameter entities, which may allow remote file disclosure.