VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,331)

page 52 of 67
  • CVE-2024-45086MedNov 4, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.

  • CVE-2024-45072MedOct 16, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.

  • CVE-2024-25971MedMar 28, 2024
    risk 0.36cvss 5.5epss 0.01

    Dell PowerProtect Data Manager, version 19.15, contains an XML External Entity Injection vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to information disclosure, denial-of-service.

  • CVE-2023-25926MedFeb 29, 2024
    risk 0.36cvss 5.5epss 0.01

    IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. …

  • CVE-2024-1167MedFeb 1, 2024
    risk 0.36cvss 5.5epss 0.01

    When SEW-EURODRIVE MOVITOOLS MotionStudio processes XML information unrestricted file access can occur.

  • CVE-2024-22380MedJan 24, 2024
    risk 0.36cvss 5.5epss 0.00

    Electronic Delivery Check System (Ministry of Agriculture, Forestry and Fisheries The Agriculture and Rural Development Project Version) March, Heisei 31 era edition Ver.14.0.001.002 and earlier improperly restricts XML external entity references (XXE). By processing a specially…

  • CVE-2024-21796MedJan 24, 2024
    risk 0.36cvss 5.5epss 0.00

    Electronic Deliverables Creation Support Tool (Construction Edition) prior to Ver1.0.4 and Electronic Deliverables Creation Support Tool (Design & Survey Edition) prior to Ver1.0.4 improperly restrict XML external entity references (XXE). By processing a specially crafted XML…

  • CVE-2024-21765MedJan 24, 2024
    risk 0.36cvss 5.5epss 0.00

    Electronic Delivery Check System (Doboku) Ver.18.1.0 and earlier, Electronic Delivery Check System (Dentsu) Ver.12.1.0 and earlier, Electronic Delivery Check System (Kikai) Ver.10.1.0 and earlier, and Electronic delivery item Inspection Support SystemVer.4.0.31 and earlier…

  • CVE-2023-5136MedNov 8, 2023
    risk 0.36cvss 5.5epss 0.00

    An incorrect permission assignment in the TopoGrafix DataPlugin for GPX could result in information disclosure. An attacker could exploit this vulnerability by getting a user to open a specially crafted data file.

  • CVE-2023-46802MedNov 6, 2023
    risk 0.36cvss 5.5epss 0.00

    e-Tax software Version3.0.10 and earlier improperly restricts XML external entity references (XXE) due to the configuration of the embedded XML parser. By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.

  • CVE-2023-43624MedOct 23, 2023
    risk 0.36cvss 5.5epss 0.00

    CX-Designer Ver.3.740 and earlier (included in CX-One CXONE-AL[][]D-V4) contains an improper restriction of XML external entity reference (XXE) vulnerability. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where…

  • CVE-2022-32755MedOct 14, 2023
    risk 0.36cvss 5.5epss 0.01

    IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 228505.

  • CVE-2023-42132MedOct 2, 2023
    risk 0.36cvss 5.5epss 0.00

    FD Application Apr. 2022 Edition (Version 9.01) and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.

  • CVE-2023-3892MedSep 19, 2023
    risk 0.36cvss 5.6epss 0.00

    Improper Restriction of XML External Entity Reference vulnerability in MIM Assistant and Client DICOM RTst Loading modules allows XML Entity Linking / XML External Entities Blowup. In order to take advantage of this vulnerability, an attacker must craft a malicious XML…

  • CVE-2023-24620MedAug 25, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Esoteric YamlBeans through 1.15. A crafted YAML document is able perform am XML Entity Expansion attack against YamlBeans YamlReader. By exploiting the Anchor feature in YAML, it is possible to generate a small YAML document that, when read, is…

  • CVE-2023-32639MedJul 25, 2023
    risk 0.36cvss 5.5epss 0.00

    Applicant Programme Ver.7.06 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.

  • CVE-2023-32635MedJul 19, 2023
    risk 0.36cvss 5.5epss 0.00

    XBRL data create application version 7.0 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XBRL file, arbitrary files on the system may be read by an attacker.

  • CVE-2023-37200MedJul 12, 2023
    risk 0.36cvss 5.5epss 0.00

    A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause loss of confidentiality when replacing a project file on the local filesystem and after manual restart of the server.

  • CVE-2023-3276MedJun 15, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability, which was classified as problematic, has been found in Dromara HuTool up to 5.8.19. Affected by this issue is the function readBySax of the file XmlUtil.java of the component XML Parsing Module. The manipulation leads to xml external entity reference. The…

  • CVE-2023-29498MedJun 13, 2023
    risk 0.36cvss 5.5epss 0.00

    Improper restriction of XML external entity reference (XXE) vulnerability exists in FRENIC RHC Loader v1.1.0.3 and earlier. If a user opens a specially crafted project file, sensitive information on the system where the affected product is installed may be disclosed.