CWE-611
Improper Restriction of XML External Entity Reference
Description
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-221
CVEs mapped to this weakness (1,331)
page 4 of 67| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-24189 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2023 | An XML External Entity (XXE) vulnerability in urule v2.1.7 allows attackers to execute arbitrary code via uploading a crafted XML file to /urule/common/saveFile. | ||
| CVE-2022-47873 | Cri | 0.64 | 9.8 | 0.01 | Jan 31, 2023 | Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote). | ||
| CVE-2022-3980 | Cri | 0.64 | 9.8 | 0.08 | Nov 16, 2022 | An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4. | ||
| CVE-2022-45400 | Cri | 0.64 | 9.8 | 0.01 | Nov 15, 2022 | Jenkins JAPEX Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | ||
| CVE-2022-45396 | Cri | 0.64 | 9.8 | 0.01 | Nov 15, 2022 | Jenkins SourceMonitor Plugin 0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | ||
| CVE-2022-45395 | Cri | 0.64 | 9.8 | 0.01 | Nov 15, 2022 | Jenkins CCCC Plugin 0.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | ||
| CVE-2022-39135 | Cri | 0.64 | 9.8 | 0.02 | Sep 11, 2022 | Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity references in their configuration, making them vulnerable to a potential XML External Entity (XXE) attack. Therefore any client… | ||
| CVE-2015-8031 | Cri | 0.64 | 9.8 | 0.02 | Jul 18, 2022 | Hudson (aka org.jvnet.hudson.main:hudson-core) before 3.3.2 allows XXE attacks. | ||
| CVE-2022-35741 | Cri | 0.64 | 9.8 | 0.08 | Jul 18, 2022 | Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerable to XML external entity (XXE) injection. This plugin is not enabled by default and the attacker would require that this plugin be enabled to exploit the… | ||
| CVE-2022-32533 | Cri | 0.64 | 9.8 | 0.04 | Jul 6, 2022 | Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option "xss.filter.post = true" may mitigate these issues. NOTE: Apache Jetspeed is a dormant project of… | ||
| CVE-2021-45024 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2022 | ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE). | ||
| CVE-2021-45981 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack. | ||
| CVE-2022-28890 | Cri | 0.64 | 9.8 | 0.03 | May 5, 2022 | A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities. | ||
| CVE-2022-24449 | Cri | 0.64 | 9.8 | 0.02 | Apr 28, 2022 | Solar appScreener through 3.10.4, when a valid license is not present, allows XXE and SSRF attacks via a crafted XML document. | ||
| CVE-2021-43142 | Cri | 0.64 | 9.8 | 0.01 | Mar 30, 2022 | An XML External Entity (XXE) vulnerability exists in wuta jox 1.16 in the readObject method in JOXSAXBeanInput. | ||
| CVE-2022-24340 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible. | ||
| CVE-2021-46660 | Cri | 0.64 | 9.8 | 0.01 | Jan 30, 2022 | Signiant Manager+Agents before 15.1 allows XML External Entity (XXE) attacks. | ||
| CVE-2021-40722 | Cri | 0.64 | 9.8 | 0.03 | Jan 13, 2022 | AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that could be abused by an attacker to achieve RCE. | ||
| CVE-2021-38298 | Cri | 0.64 | 9.8 | 0.03 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE. | ||
| CVE-2021-34436 | Cri | 0.64 | 9.8 | 0.02 | Sep 2, 2021 | In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. This extension uses lsp4xml (recently renamed to LemMinX) in order to provide language support for XML. This is installed by… |
- risk 0.64cvss 9.8epss 0.01
An XML External Entity (XXE) vulnerability in urule v2.1.7 allows attackers to execute arbitrary code via uploading a crafted XML file to /urule/common/saveFile.
- risk 0.64cvss 9.8epss 0.01
Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote).
- risk 0.64cvss 9.8epss 0.08
An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4.
- risk 0.64cvss 9.8epss 0.01
Jenkins JAPEX Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- risk 0.64cvss 9.8epss 0.01
Jenkins SourceMonitor Plugin 0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- risk 0.64cvss 9.8epss 0.01
Jenkins CCCC Plugin 0.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- risk 0.64cvss 9.8epss 0.02
Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity references in their configuration, making them vulnerable to a potential XML External Entity (XXE) attack. Therefore any client…
- risk 0.64cvss 9.8epss 0.02
Hudson (aka org.jvnet.hudson.main:hudson-core) before 3.3.2 allows XXE attacks.
- risk 0.64cvss 9.8epss 0.08
Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerable to XML external entity (XXE) injection. This plugin is not enabled by default and the attacker would require that this plugin be enabled to exploit the…
- risk 0.64cvss 9.8epss 0.04
Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option "xss.filter.post = true" may mitigate these issues. NOTE: Apache Jetspeed is a dormant project of…
- risk 0.64cvss 9.8epss 0.01
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).
- risk 0.64cvss 9.8epss 0.01
NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack.
- risk 0.64cvss 9.8epss 0.03
A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities.
- risk 0.64cvss 9.8epss 0.02
Solar appScreener through 3.10.4, when a valid license is not present, allows XXE and SSRF attacks via a crafted XML document.
- risk 0.64cvss 9.8epss 0.01
An XML External Entity (XXE) vulnerability exists in wuta jox 1.16 in the readObject method in JOXSAXBeanInput.
- risk 0.64cvss 9.8epss 0.01
In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible.
- risk 0.64cvss 9.8epss 0.01
Signiant Manager+Agents before 15.1 allows XML External Entity (XXE) attacks.
- risk 0.64cvss 9.8epss 0.03
AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that could be abused by an attacker to achieve RCE.
- risk 0.64cvss 9.8epss 0.03
Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.
- risk 0.64cvss 9.8epss 0.02
In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. This extension uses lsp4xml (recently renamed to LemMinX) in order to provide language support for XML. This is installed by…