VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,372)

page 47 of 69
  • CVE-2020-8541MedJun 16, 2020
    risk 0.42cvss 6.5epss 0.01

    OX App Suite through 7.10.3 allows XXE attacks.

  • CVE-2020-12642HigMay 4, 2020
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in service-api before 4.3.12 and 5.x before 5.1.1 for Report Portal. It allows XXE, with resultant secrets disclosure and SSRF, via JUnit XML launch import.

  • CVE-2019-17020MedJan 8, 2020
    risk 0.42cvss 6.5epss 0.01

    If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Security Policy will not be applied to the contents of the XSL stylesheet. If the XSL sheet e.g. includes JavaScript, it would bypass any of the restrictions of the…

  • CVE-2019-3768MedJan 3, 2020
    risk 0.42cvss 6.5epss 0.01

    RSA Authentication Manager versions prior to 8.4 P7 contain an XML Entity Injection Vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to cause information disclosure of local system files by supplying specially crafted XML message.

  • CVE-2012-2656HigDec 18, 2019
    risk 0.42cvss 7.5epss 0.02

    An XML eXternal Entity (XXE) issue exists in Restlet 1.1.10 in an endpoint using XML transport, which lets a remote attacker obtain sensitive information.

  • CVE-2014-3643HigDec 15, 2019
    risk 0.42cvss 7.5epss 0.02

    jersey: XXE via parameter entities not disabled by the jersey SAX parser

  • CVE-2019-19702HigDec 10, 2019
    risk 0.42cvss 7.5epss 0.01

    The modoboa-dmarc plugin 1.1.0 for Modoboa is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this to perform a denial of service against the DMARC reporting functionality, such as by referencing the…

  • CVE-2019-11216MedDec 4, 2019
    risk 0.42cvss 6.5epss 0.02

    BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attacks to download local files from the server, or do DoS attacks with XML expansion attacks. XXE with direct response and XXE OOB are…

  • CVE-2019-17085MedNov 18, 2019
    risk 0.42cvss 6.5epss 0.01

    XXE attack vulnerability on Micro Focus Operations Agent, affected version 12.0, 12.01, 12.02, 12.03, 12.04, 12.05, 12.06, 12.10, 12.11. The vulnerability could be exploited to do an XXE attack on Operations Agent.

  • CVE-2019-14276MedOct 23, 2019
    risk 0.42cvss 6.5epss 0.01

    WUSTL XNAT 1.7.5.3 allows XXE attacks via a POST request body.

  • CVE-2019-12711MedOct 2, 2019
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of service (DoS)…

  • CVE-2019-15641MedAug 26, 2019
    risk 0.42cvss 6.5epss 0.01

    xmlrpc.cgi in Webmin through 1.930 allows authenticated XXE attacks. By default, only root, admin, and sysadm can access xmlrpc.cgi.

  • CVE-2019-1010202MedJul 23, 2019
    risk 0.42cvss 6.5epss 0.01

    Jeesite 1.2.7 is affected by: XML External Entity (XXE). The impact is: sensitive information disclosure. The component is: convertToModel() function in src/main/java/com.thinkgem.jeesite/modules/act/service/ActProcessService.java. The attack vector is: network…

  • CVE-2018-17152MedJul 11, 2019
    risk 0.42cvss 6.4epss 0.01

    Intersystems Cache 2017.2.2.865.0 allows XXE.

  • CVE-2019-1903MedJun 20, 2019
    risk 0.42cvss 6.5epss 0.02

    A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of service (DoS) condition. The vulnerability is due to improper restrictions on XML entities. An attacker could exploit this vulnerability…

  • CVE-2019-10337HigJun 11, 2019
    risk 0.42cvss 7.5epss 0.02

    An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to control a the content of the input file for the "XML" macro to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins…

  • CVE-2018-17289MedApr 18, 2019
    risk 0.42cvss 6.5epss 0.01

    An XML external entity (XXE) vulnerability in Kofax Front Office Server Administration Console version 4.1.1.11.0.5212 allows remote authenticated users to read arbitrary files via crafted XML inside an imported package configuration (.ZIP file) within the…

  • CVE-2017-18110MedMar 29, 2019
    risk 0.42cvss 6.5epss 0.01

    The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to read files from the filesystem via a XXE vulnerability.

  • CVE-2019-0277MedMar 12, 2019
    risk 0.42cvss 6.5epss 0.02

    SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space (XML External Entity vulnerability).

  • CVE-2018-20233MedJan 18, 2019
    risk 0.42cvss 6.5epss 0.02

    The Upload add-on resource in Atlassian Universal Plugin Manager before version 2.22.14 allows remote attackers who have system administrator privileges to read files, make network requests and perform a denial of service attack via an XML External Entity vulnerability in the…