CWE-611
Improper Restriction of XML External Entity Reference
Description
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-221
CVEs mapped to this weakness (1,331)
page 46 of 67| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-11216 | Med | 0.42 | 6.5 | 0.02 | Dec 4, 2019 | BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attacks to download local files from the server, or do DoS attacks with XML expansion attacks. XXE with direct response and XXE OOB are… | ||
| CVE-2019-17085 | Med | 0.42 | 6.5 | 0.01 | Nov 18, 2019 | XXE attack vulnerability on Micro Focus Operations Agent, affected version 12.0, 12.01, 12.02, 12.03, 12.04, 12.05, 12.06, 12.10, 12.11. The vulnerability could be exploited to do an XXE attack on Operations Agent. | ||
| CVE-2019-14276 | Med | 0.42 | 6.5 | 0.01 | Oct 23, 2019 | WUSTL XNAT 1.7.5.3 allows XXE attacks via a POST request body. | ||
| CVE-2019-12711 | Med | 0.42 | 6.5 | 0.01 | Oct 2, 2019 | A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of service (DoS)… | ||
| CVE-2019-15641 | Med | 0.42 | 6.5 | 0.01 | Aug 26, 2019 | xmlrpc.cgi in Webmin through 1.930 allows authenticated XXE attacks. By default, only root, admin, and sysadm can access xmlrpc.cgi. | ||
| CVE-2019-1010202 | Med | 0.42 | 6.5 | 0.01 | Jul 23, 2019 | Jeesite 1.2.7 is affected by: XML External Entity (XXE). The impact is: sensitive information disclosure. The component is: convertToModel() function in src/main/java/com.thinkgem.jeesite/modules/act/service/ActProcessService.java. The attack vector is: network… | ||
| CVE-2018-17152 | Med | 0.42 | 6.4 | 0.01 | Jul 11, 2019 | Intersystems Cache 2017.2.2.865.0 allows XXE. | ||
| CVE-2019-1903 | Med | 0.42 | 6.5 | 0.02 | Jun 20, 2019 | A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of service (DoS) condition. The vulnerability is due to improper restrictions on XML entities. An attacker could exploit this vulnerability… | ||
| CVE-2019-10337 | Hig | 0.42 | 7.5 | 0.02 | Jun 11, 2019 | An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to control a the content of the input file for the "XML" macro to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins… | ||
| CVE-2018-17289 | Med | 0.42 | 6.5 | 0.02 | Apr 18, 2019 | An XML external entity (XXE) vulnerability in Kofax Front Office Server Administration Console version 4.1.1.11.0.5212 allows remote authenticated users to read arbitrary files via crafted XML inside an imported package configuration (.ZIP file) within the… | ||
| CVE-2017-18110 | Med | 0.42 | 6.5 | 0.01 | Mar 29, 2019 | The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to read files from the filesystem via a XXE vulnerability. | ||
| CVE-2019-0277 | Med | 0.42 | 6.5 | 0.02 | Mar 12, 2019 | SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space (XML External Entity vulnerability). | ||
| CVE-2018-20233 | Med | 0.42 | 6.5 | 0.02 | Jan 18, 2019 | The Upload add-on resource in Atlassian Universal Plugin Manager before version 2.22.14 allows remote attackers who have system administrator privileges to read files, make network requests and perform a denial of service attack via an XML External Entity vulnerability in the… | ||
| CVE-2018-1000840 | Med | 0.42 | 6.5 | 0.02 | Dec 20, 2018 | Processing Foundation Processing version 3.4 and earlier contains a XML External Entity (XXE) vulnerability in loadXML() function that can result in An attacker can read arbitrary files and exfiltrate their contents via HTTP requests. This attack appear to be exploitable via The… | ||
| CVE-2018-20298 | Med | 0.42 | 6.5 | 0.01 | Dec 19, 2018 | S3 Browser before 8.1.5 contains an XML external entity (XXE) vulnerability, allowing remote attackers to read arbitrary files and obtain NTLMv2 hash values by tricking a user into connecting to a malicious server via the S3 protocol. | ||
| CVE-2018-12471 | Med | 0.42 | 6.5 | 0.02 | Oct 4, 2018 | A External Entity Reference ('XXE') vulnerability in SUSE Linux SMT allows remote attackers to read data from the server or cause DoS by referencing blocking elements. Affected releases are SUSE Linux SMT: versions prior to 3.0.37. | ||
| CVE-2018-5433 | Med | 0.42 | 6.5 | 0.01 | Jun 13, 2018 | The TIBCO Administrator server component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, and TIBCO Administrator - Enterprise Edition for z/Linux contains vulnerabilities wherein a malicious user could perform XML external entity expansion (XXE) attacks to… | ||
| CVE-2018-1000198 | Med | 0.42 | 6.5 | 0.01 | Jun 5, 2018 | A XML external entity processing vulnerability exists in Jenkins Black Duck Hub Plugin 3.1.0 and older in PostBuildScanDescriptor.java that allows attackers with Overall/Read permission to make Jenkins process XML eternal entities in an XML document. | ||
| CVE-2018-10175 | Med | 0.42 | 6.5 | 0.01 | Apr 20, 2018 | Digital Guardian Management Console 7.1.2.0015 has an XXE issue. | ||
| CVE-2015-7461 | Med | 0.42 | 6.5 | 0.01 | Mar 20, 2018 | XML external entity (XXE) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote authenticated users to cause a denial of service (memory consumption) via crafted XML data. IBM X-Force ID: 108357. |
- risk 0.42cvss 6.5epss 0.02
BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attacks to download local files from the server, or do DoS attacks with XML expansion attacks. XXE with direct response and XXE OOB are…
- risk 0.42cvss 6.5epss 0.01
XXE attack vulnerability on Micro Focus Operations Agent, affected version 12.0, 12.01, 12.02, 12.03, 12.04, 12.05, 12.06, 12.10, 12.11. The vulnerability could be exploited to do an XXE attack on Operations Agent.
- risk 0.42cvss 6.5epss 0.01
WUSTL XNAT 1.7.5.3 allows XXE attacks via a POST request body.
- risk 0.42cvss 6.5epss 0.01
A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of service (DoS)…
- risk 0.42cvss 6.5epss 0.01
xmlrpc.cgi in Webmin through 1.930 allows authenticated XXE attacks. By default, only root, admin, and sysadm can access xmlrpc.cgi.
- risk 0.42cvss 6.5epss 0.01
Jeesite 1.2.7 is affected by: XML External Entity (XXE). The impact is: sensitive information disclosure. The component is: convertToModel() function in src/main/java/com.thinkgem.jeesite/modules/act/service/ActProcessService.java. The attack vector is: network…
- risk 0.42cvss 6.4epss 0.01
Intersystems Cache 2017.2.2.865.0 allows XXE.
- risk 0.42cvss 6.5epss 0.02
A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of service (DoS) condition. The vulnerability is due to improper restrictions on XML entities. An attacker could exploit this vulnerability…
- risk 0.42cvss 7.5epss 0.02
An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to control a the content of the input file for the "XML" macro to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins…
- risk 0.42cvss 6.5epss 0.02
An XML external entity (XXE) vulnerability in Kofax Front Office Server Administration Console version 4.1.1.11.0.5212 allows remote authenticated users to read arbitrary files via crafted XML inside an imported package configuration (.ZIP file) within the…
- risk 0.42cvss 6.5epss 0.01
The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to read files from the filesystem via a XXE vulnerability.
- risk 0.42cvss 6.5epss 0.02
SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space (XML External Entity vulnerability).
- risk 0.42cvss 6.5epss 0.02
The Upload add-on resource in Atlassian Universal Plugin Manager before version 2.22.14 allows remote attackers who have system administrator privileges to read files, make network requests and perform a denial of service attack via an XML External Entity vulnerability in the…
- risk 0.42cvss 6.5epss 0.02
Processing Foundation Processing version 3.4 and earlier contains a XML External Entity (XXE) vulnerability in loadXML() function that can result in An attacker can read arbitrary files and exfiltrate their contents via HTTP requests. This attack appear to be exploitable via The…
- risk 0.42cvss 6.5epss 0.01
S3 Browser before 8.1.5 contains an XML external entity (XXE) vulnerability, allowing remote attackers to read arbitrary files and obtain NTLMv2 hash values by tricking a user into connecting to a malicious server via the S3 protocol.
- risk 0.42cvss 6.5epss 0.02
A External Entity Reference ('XXE') vulnerability in SUSE Linux SMT allows remote attackers to read data from the server or cause DoS by referencing blocking elements. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.
- risk 0.42cvss 6.5epss 0.01
The TIBCO Administrator server component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, and TIBCO Administrator - Enterprise Edition for z/Linux contains vulnerabilities wherein a malicious user could perform XML external entity expansion (XXE) attacks to…
- risk 0.42cvss 6.5epss 0.01
A XML external entity processing vulnerability exists in Jenkins Black Duck Hub Plugin 3.1.0 and older in PostBuildScanDescriptor.java that allows attackers with Overall/Read permission to make Jenkins process XML eternal entities in an XML document.
- risk 0.42cvss 6.5epss 0.01
Digital Guardian Management Console 7.1.2.0015 has an XXE issue.
- risk 0.42cvss 6.5epss 0.01
XML external entity (XXE) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote authenticated users to cause a denial of service (memory consumption) via crafted XML data. IBM X-Force ID: 108357.