VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,372)

page 32 of 69
  • CVE-2017-15725HigOct 28, 2019
    risk 0.49cvss 7.5epss 0.01

    An XML External Entity Injection vulnerability exists in Dzone AnswerHub.

  • CVE-2019-8087HigOct 25, 2019
    risk 0.49cvss 7.5epss 0.04

    Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2019-8082HigOct 25, 2019
    risk 0.49cvss 7.5epss 0.03

    Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2019-6179HigSep 3, 2019
    risk 0.49cvss 7.5epss 0.01

    An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) prior to version 2.5.0 , Lenovo XClarity Integrator (LXCI) for Microsoft System Center prior to version 7.7.0, and Lenovo XClarity Integrator (LXCI) for VMWare vCenter…

  • CVE-2019-14258HigAug 21, 2019
    risk 0.49cvss 7.5epss 0.02

    The XML-RPC subsystem in Zenoss 2.5.3 allows XXE attacks that lead to unauthenticated information disclosure via port 9988.

  • CVE-2019-15160HigAug 19, 2019
    risk 0.49cvss 7.5epss 0.02

    The SweetXml (aka sweet_xml) package through 0.6.6 for Erlang and Elixir allows attackers to cause a denial of service (resource consumption) via an XML entity expansion attack with an inline DTD.

  • CVE-2019-1057HigAug 14, 2019
    risk 0.49cvss 7.5epss 0.03

    A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exploited the vulnerability could run malicious code remotely to take control of the user’s system. To exploit the vulnerability,…

  • CVE-2019-13176HigAug 8, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2. The Content.MainForm.wgx component is affected by XXE via a crafted XML document in POST data. There is potential to use this for SSRF (reading local files, outbound HTTP,…

  • CVE-2018-14383HigAug 7, 2019
    risk 0.49cvss 7.5epss 0.01

    The Transition Technologies "The Scheduler" app 5.1.3 for Jira allows XXE due to a weakly configured/parameterized XML parser. It was fixed in the versions 5.2.1 and 3.3.7

  • CVE-2019-7847HigJul 18, 2019
    risk 0.49cvss 7.5epss 0.03

    Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper Restriction of XML External Entity Reference ('XXE') vulnerability. Successful exploitation could lead to Arbitrary read access to the file system in the context of the current user.

  • CVE-2019-11392HigJun 21, 2019
    risk 0.49cvss 7.5epss 0.01

    BlogEngine.NET 3.3.7 and earlier allows XXE via an apml file to syndication.axd.

  • CVE-2019-10718HigJun 21, 2019
    risk 0.49cvss 7.5epss 0.02

    BlogEngine.NET 3.3.7.0 and earlier allows XML External Entity Blind Injection, related to pingback.axd and BlogEngine.Core/Web/HttpHandlers/PingbackHandler.cs.

  • CVE-2019-3722HigJun 6, 2019
    risk 0.49cvss 7.5epss 0.04

    Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external entity (XXE) injection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to read arbitrary server system files by…

  • CVE-2019-8999HigApr 18, 2019
    risk 0.49cvss 7.5epss 0.01

    An XML External Entity vulnerability in the UEM Core of BlackBerry UEM version(s) earlier than 12.10.1a could allow an attacker to potentially gain read access to files on any system reachable by the UEM service account.

  • CVE-2019-10244HigApr 9, 2019
    risk 0.49cvss 7.5epss 0.02

    In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service (not part of the device distribution) could potentially be target of XXE attack due to an improper factory and parser…

  • CVE-2019-9761HigMar 14, 2019
    risk 0.49cvss 7.5epss 0.01

    An XXE issue was discovered in PHPSHE 1.7, which can be used to read any file in the system or scan the internal network without authentication. This occurs because of the call to wechat_getxml in include/plugin/payment/wechat/notify_url.php.

  • CVE-2018-20733HigJan 17, 2019
    risk 0.49cvss 7.5epss 0.01

    BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE.

  • CVE-2018-7837HigDec 24, 2018
    risk 0.49cvss 7.5epss 0.01

    An Improper Restriction of XML External Entity Reference ('XXE') vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow the software to resolve documents outside of the intended sphere of control, causing the software to embed incorrect…

  • CVE-2018-20157HigDec 15, 2018
    risk 0.49cvss 7.5epss 0.02

    The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zip) file, allowing attackers to read arbitrary files.

  • CVE-2018-17912HigNov 2, 2018
    risk 0.49cvss 7.5epss 0.01

    An XXE vulnerability exists in CASE Suite Versions 3.10 and prior when processing parameter entities, which may allow remote file disclosure.