VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,331)

page 45 of 67
  • CVE-2021-25164MedApr 28, 2021
    risk 0.42cvss 6.5epss 0.01

    A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

  • CVE-2021-28965HigApr 21, 2021
    risk 0.42cvss 7.5epss 0.05

    The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing.

  • CVE-2021-27604MedApr 14, 2021
    risk 0.42cvss 6.5epss 0.01

    In order to prevent XML External Entity vulnerability in SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Enterprise Service Repository JAVA Mappings), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50, SAP recommends to refer this note.

  • CVE-2021-29421HigApr 1, 2021
    risk 0.42cvss 7.5epss 0.02

    models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.

  • CVE-2021-26969MedMar 5, 2021
    risk 0.42cvss 6.5epss 0.01

    A remote authenticated authenticated xml external entity (xxe) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Due to improper restrictions on XML entities a vulnerability exists in the web-based management interface of AirWave. A…

  • CVE-2020-26981MedJan 12, 2021
    risk 0.42cvss 6.5epss 0.03

    A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). When opening a specially crafted xml file, the application could disclose arbitrary files to remote attackers. This is because of the passing of specially…

  • CVE-2020-35123MedDec 17, 2020
    risk 0.42cvss 6.5epss 0.01

    In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store extension, which is vulnerable to XXE attacks. This has been fixed in Zimbra Collaboration Suite Network edition 9.0.0 Patch 10 and…

  • CVE-2020-29436MedDec 17, 2020
    risk 0.42cvss 6.5epss 0.01

    Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of NXRM via an XXE vulnerability. Fixed in version 3.29.0.

  • CVE-2020-2324HigDec 3, 2020
    risk 0.42cvss 7.5epss 0.01

    Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2020-2298MedOct 8, 2020
    risk 0.42cvss 6.5epss 0.01

    Jenkins Nerrvana Plugin 1.02.06 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2020-25750HigSep 18, 2020
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in DotPlant2 before 2020-09-14. In class Pay2PayPayment in payment/Pay2PayPayment.php, there is an XXE vulnerability in the checkResult function. The user input ($_POST['xml']) is used for simplexml_load_string without sanitization. NOTE: This…

  • CVE-2020-2247MedSep 1, 2020
    risk 0.42cvss 6.5epss 0.01

    Jenkins Klocwork Analysis Plugin 2020.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2020-24591MedAug 21, 2020
    risk 0.42cvss 6.5epss 0.01

    The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager Analytics 2.2.0 and 2.5.0, API Microgateway 2.2.0, Enterprise Integrator 6.2.0 and 6.3.0, and Identity Server Analytics through…

  • CVE-2020-8541MedJun 16, 2020
    risk 0.42cvss 6.5epss 0.01

    OX App Suite through 7.10.3 allows XXE attacks.

  • CVE-2020-12642HigMay 4, 2020
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in service-api before 4.3.12 and 5.x before 5.1.1 for Report Portal. It allows XXE, with resultant secrets disclosure and SSRF, via JUnit XML launch import.

  • CVE-2019-17020MedJan 8, 2020
    risk 0.42cvss 6.5epss 0.01

    If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Security Policy will not be applied to the contents of the XSL stylesheet. If the XSL sheet e.g. includes JavaScript, it would bypass any of the restrictions of the…

  • CVE-2019-3768MedJan 3, 2020
    risk 0.42cvss 6.5epss 0.01

    RSA Authentication Manager versions prior to 8.4 P7 contain an XML Entity Injection Vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to cause information disclosure of local system files by supplying specially crafted XML message.

  • CVE-2012-2656HigDec 18, 2019
    risk 0.42cvss 7.5epss 0.02

    An XML eXternal Entity (XXE) issue exists in Restlet 1.1.10 in an endpoint using XML transport, which lets a remote attacker obtain sensitive information.

  • CVE-2014-3643HigDec 15, 2019
    risk 0.42cvss 7.5epss 0.02

    jersey: XXE via parameter entities not disabled by the jersey SAX parser

  • CVE-2019-19702HigDec 10, 2019
    risk 0.42cvss 7.5epss 0.01

    The modoboa-dmarc plugin 1.1.0 for Modoboa is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this to perform a denial of service against the DMARC reporting functionality, such as by referencing the…