VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,331)

page 37 of 67
  • CVE-2022-43941HigApr 3, 2023
    risk 0.46cvss 7.1epss 0.01

    Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly protect the Post Analysis service endpoint of the data access plugin against out-of-band XML External Entity Reference. 

  • CVE-2023-28685HigMar 22, 2023
    risk 0.46cvss 7.1epss 0.01

    Jenkins AbsInt a³ Plugin 1.1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2023-27476HigMar 8, 2023
    risk 0.46cvss 8.2epss 0.01

    OWSLib is a Python package for client programming with Open Geospatial Consortium (OGC) web service interface standards, and their related content models. OWSLib's XML parser (which supports both `lxml` and `xml.etree`) does not disable entity resolution, and could lead to…

  • CVE-2022-38389HigFeb 3, 2023
    risk 0.46cvss 7.1epss 0.01

    IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 233975.

  • CVE-2022-34348HigSep 23, 2022
    risk 0.46cvss 7.1epss 0.01

    IBM Sterling Partner Engagement Manager 6.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 230017.

  • CVE-2022-22358HigJul 19, 2022
    risk 0.46cvss 7.1epss 0.01

    IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM…

  • CVE-2022-22977HigMay 24, 2022
    risk 0.46cvss 7.1epss 0.01

    VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious actor with non-administrative local user privileges in the Windows guest OS, where VMware Tools is installed, may exploit this issue leading to a…

  • CVE-2022-28140HigMar 29, 2022
    risk 0.46cvss 8.1epss 0.01

    Jenkins Flaky Test Handler Plugin 1.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2020-14478HigFeb 24, 2022
    risk 0.46cvss 7.1epss 0.00

    A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a denial-of-service condition and allow the attacker to arbitrarily read any local…

  • CVE-2021-23463HigDec 10, 2021
    risk 0.46cvss 8.1epss 0.03

    The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcResultSet.getSQLXML() method. If it executes the getSource()…

  • CVE-2019-4730HigJun 1, 2021
    risk 0.46cvss 7.1epss 0.02

    IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 172533.

  • CVE-2021-20502HigMar 30, 2021
    risk 0.46cvss 7.1epss 0.01

    IBM Jazz Foundation Products are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 198059.

  • CVE-2021-20482HigMar 30, 2021
    risk 0.46cvss 7.1epss 0.01

    IBM Cloud Pak for Automation 20.0.2 and 20.0.3 IF002 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 197504.

  • CVE-2020-27148HigJan 12, 2021
    risk 0.46cvss 7.1epss 0.01

    The TIBCO EBX Add-on for Oracle Hyperion EPM, TIBCO EBX Data Exchange Add-on, and TIBCO EBX Insight Add-on components of TIBCO Software Inc.'s TIBCO EBX Add-ons contain a vulnerability that theoretically allows a low privileged attacker with network access to execute an XML…

  • CVE-2020-2284HigSep 23, 2020
    risk 0.46cvss 7.1epss 0.01

    Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2020-2245HigSep 1, 2020
    risk 0.46cvss 7.1epss 0.01

    Jenkins Valgrind Plugin 0.28 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2019-17637HigJul 15, 2020
    risk 0.46cvss 7.1epss 0.01

    In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in…

  • CVE-2020-4246HigMay 28, 2020
    risk 0.46cvss 7.1epss 0.01

    IBM Security Identity Governance and Intelligence 5.2.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 175481.

  • CVE-2020-2178HigApr 16, 2020
    risk 0.46cvss 7.1epss 0.01

    Jenkins Parasoft Findings Plugin 10.4.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2019-4707HigJan 28, 2020
    risk 0.46cvss 7.1epss 0.01

    IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 172018.