VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,331)

page 53 of 67
  • CVE-2023-2806MedMay 19, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability classified as problematic was found in Weaver e-cology up to 9.0. Affected by this vulnerability is the function RequestInfoByXml of the component API. The manipulation leads to xml external entity reference. The associated identifier of this vulnerability is…

  • CVE-2022-45876MedApr 26, 2023
    risk 0.36cvss 5.5epss 0.03

    Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.

  • CVE-2023-27652MedApr 20, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges cause a denial of service via the update_info field of the _default_.xml file.

  • CVE-2023-26264MedApr 13, 2023
    risk 0.36cvss 5.5epss 0.00

    All versions of Talend Data Catalog before 8.0-20220907 are potentially vulnerable to XML External Entity (XXE) attacks in the license parsing code.

  • CVE-2023-26263MedApr 13, 2023
    risk 0.36cvss 5.5epss 0.00

    All versions of Talend Data Catalog before 8.0-20230110 are potentially vulnerable to XML External Entity (XXE) attacks in the /MIMBWebServices/license endpoint of the remote harvesting server.

  • CVE-2023-25955MedApr 11, 2023
    risk 0.36cvss 5.5epss 0.00

    National land numerical information data conversion tool all versions improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the PC may be accessed by an attacker.

  • CVE-2022-46300MedMar 21, 2023
    risk 0.36cvss 5.5epss 0.04

    Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.

  • CVE-2022-45468MedMar 21, 2023
    risk 0.36cvss 5.5epss 0.02

    Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.

  • CVE-2022-45121MedMar 21, 2023
    risk 0.36cvss 5.5epss 0.00

    Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.

  • CVE-2022-43512MedMar 21, 2023
    risk 0.36cvss 5.5epss 0.00

    Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.

  • CVE-2022-41696MedMar 21, 2023
    risk 0.36cvss 5.5epss 0.00

    Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.

  • CVE-2023-22322MedJan 30, 2023
    risk 0.36cvss 5.5epss 0.00

    Improper restriction of XML external entity reference (XXE) vulnerability exists in OMRON CX-Motion Pro 1.4.6.013 and earlier. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Motion Pro is installed may…

  • CVE-2021-4311MedJan 9, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability classified as problematic was found in Talend Open Studio for MDM. This vulnerability affects unknown code of the component XML Handler. The manipulation leads to xml external entity reference. The patch is identified as 31d442b9fb1d518128fd18f6e4d54e06c3d67793.…

  • CVE-2022-4818MedDec 28, 2022
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in Talend Open Studio for MDM. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file org.talend.mdm.core/src/com/amalto/core/storage/SystemStorageWrapper.java. The manipulation leads to xml external…

  • CVE-2022-45386MedNov 15, 2022
    risk 0.36cvss 5.5epss 0.00

    Jenkins Violations Plugin 0.7.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-2759MedAug 31, 2022
    risk 0.36cvss 5.5epss 0.01

    Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions where the software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control,…

  • CVE-2020-14379MedAug 16, 2022
    risk 0.36cvss 5.6epss 0.00

    A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading to denial of service and information disclosure.

  • CVE-2022-1331MedMay 3, 2022
    risk 0.36cvss 5.5epss 0.01

    In four instances DMARS (All versions prior to v2.1.10.24) does not properly restrict references of XML external entities while processing specific project files, which may allow unauthorized information disclosure.

  • CVE-2022-0221MedApr 13, 2022
    risk 0.36cvss 5.5epss 0.01

    A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information disclosure when opening a malicious solution file provided by an attacker with SCADAPack Workbench. This could be exploited to pass data from local files to a…

  • CVE-2022-1018MedApr 1, 2022
    risk 0.36cvss 5.5epss 0.02

    When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this to pass data from local files to a remote web server,…