VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,331)

page 4 of 67
  • CVE-2023-24189CriFeb 24, 2023
    risk 0.64cvss 9.8epss 0.01

    An XML External Entity (XXE) vulnerability in urule v2.1.7 allows attackers to execute arbitrary code via uploading a crafted XML file to /urule/common/saveFile.

  • CVE-2022-47873CriJan 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote).

  • CVE-2022-3980CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.08

    An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4.

  • CVE-2022-45400CriNov 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Jenkins JAPEX Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-45396CriNov 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Jenkins SourceMonitor Plugin 0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-45395CriNov 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Jenkins CCCC Plugin 0.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-39135CriSep 11, 2022
    risk 0.64cvss 9.8epss 0.02

    Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity references in their configuration, making them vulnerable to a potential XML External Entity (XXE) attack. Therefore any client…

  • CVE-2015-8031CriJul 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Hudson (aka org.jvnet.hudson.main:hudson-core) before 3.3.2 allows XXE attacks.

  • CVE-2022-35741CriJul 18, 2022
    risk 0.64cvss 9.8epss 0.08

    Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerable to XML external entity (XXE) injection. This plugin is not enabled by default and the attacker would require that this plugin be enabled to exploit the…

  • CVE-2022-32533CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.04

    Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option "xss.filter.post = true" may mitigate these issues. NOTE: Apache Jetspeed is a dormant project of…

  • CVE-2021-45024CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.01

    ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).

  • CVE-2021-45981CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack.

  • CVE-2022-28890CriMay 5, 2022
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities.

  • CVE-2022-24449CriApr 28, 2022
    risk 0.64cvss 9.8epss 0.02

    Solar appScreener through 3.10.4, when a valid license is not present, allows XXE and SSRF attacks via a crafted XML document.

  • CVE-2021-43142CriMar 30, 2022
    risk 0.64cvss 9.8epss 0.01

    An XML External Entity (XXE) vulnerability exists in wuta jox 1.16 in the readObject method in JOXSAXBeanInput.

  • CVE-2022-24340CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.01

    In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible.

  • CVE-2021-46660CriJan 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Signiant Manager+Agents before 15.1 allows XML External Entity (XXE) attacks.

  • CVE-2021-40722CriJan 13, 2022
    risk 0.64cvss 9.8epss 0.03

    AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that could be abused by an attacker to achieve RCE.

  • CVE-2021-38298CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.03

    Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.

  • CVE-2021-34436CriSep 2, 2021
    risk 0.64cvss 9.8epss 0.02

    In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. This extension uses lsp4xml (recently renamed to LemMinX) in order to provide language support for XML. This is installed by…